# SACOSI · Regulatory knowledge base (full text) > Standards and laws for companies in Switzerland and the EU, with triggers, obligations, evidence, deadlines and sources. Publisher: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch/en). As of: 24 September 2026. A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here. - Overview: https://sacosi.ch/en/norms - Regulatory Check: https://sacosi.ch/en/regulation#normencheck - Sections as JSON Lines: https://sacosi.ch/en/knowledge/normen.en.jsonl - German version: https://sacosi.ch/llms-full.txt # Regulatory Knowledge Base — Corpus Continuous text of all norms in `wissen/normen-en/`, generated from the individual `.json` files. Import for RAG and `llms-full.txt`. Each section is self-contained. This knowledge base feeds a deterministic regulatory check on sacosi.ch, a RAG, and the GEO pages. The research rests with us, not with the visitor. ## Swiss AI regulation (planned implementation of the Council of Europe Framework Convention on Artificial Intelligence) (CH AI Regulation) *ID: `ch_ki_regulierung` · Type: gesetz · Scope: CH · Basis of obligation: freiwillig · As of: 2026-09-24* ### When does CH AI Regulation apply to you? Switzerland does not yet have an AI-specific act. On 12 February 2025, the Federal Council discussed a stocktaking report on possible regulatory approaches to artificial intelligence and instructed the Federal Office of Justice (FOJ) to draft a consultation bill by the end of 2026, implementing in particular the Council of Europe's Framework Convention on Artificial Intelligence. Until this process is concluded, there is no horizontal, AI-specific legal obligation in Switzerland; existing obligations, for instance under the FADP, already apply today regardless. Triggers in detail: - **If you use AI systems** (confidence: pruefen): You use AI systems - a horizontal Swiss AI obligation does not yet exist today (as of 24.9.2026), but the consultation bill planned for the end of 2026 could bring transparency, data protection and oversight requirements for you in future. Nothing is currently binding; monitor the development. - **If you provide AI systems** (confidence: pruefen): You provide AI systems - the same recommendation to monitor developments applies to you as a provider. According to the Federal Council, the planned regulation is to combine legally binding measures with voluntary elements such as industry solutions and self-commitments; their specific content has not yet been determined. - **If you supply public-sector clients** (confidence: pruefen): You supply public-sector clients - internal requirements for the use of AI within the federal administration itself already exist outside this consultation bill; whether and how these have knock-on effects on you as a supplier needs to be checked case by case. Exceptions: - There is currently (as of 24.9.2026) no Swiss AI act and no AI ordinance; the regulation described here is a consultation bill still under preparation, with no legal force. - Sector-specific rules - for instance the FADP for automated individual decisions and profiling, or medical device law for AI in medical devices - remain unaffected by this process and already apply today regardless. ### Why **Do I already have to comply with a Swiss AI regulation today?** No. No AI-specific Swiss act exists yet. On 12 February 2025, the Federal Council merely issued the mandate to develop a consultation bill by the end of 2026 - that is an early stage of lawmaking, not a current obligation. **What is the planned bill based on?** On implementing the Council of Europe's Framework Convention on Artificial Intelligence: the consultation bill is to set out the legal measures needed in the areas of transparency, data protection, non-discrimination and oversight, combined with non-binding measures such as industry solutions or self-commitment declarations. **Which office is responsible?** The Federal Office of Justice (FOJ) coordinates the work, together with the Federal Office of Communications (OFCOM), the Directorate of International Law and other affected federal bodies. ### Obligations - No statutory obligations arise from this bill as long as it has not been passed and brought into force. - Voluntarily possible: monitoring the consultation process and participating in industry solutions or self-commitment declarations, which the Federal Council is providing for alongside the legally binding bill. Deadlines: - 2025-02-12: The Federal Council discusses a stocktaking report on possible AI regulatory approaches and instructs several offices, including the Federal Office of Justice, to develop regulatory measures. - 2026-12-31: Target date: by this point, the Federal Office of Justice is to submit a consultation bill for legally binding measures as well as an implementation plan for non-binding measures. This is a milestone for the bill, not the entry-into-force date of an act. Penalties: None. No applicable act yet exists from which penalties could be derived. ### Evidence - Not applicable, as long as no applicable law exists. Related to other norms in this knowledge base: eu_ai_act. Not evidenced / open: - The exact substantive content of the future consultation bill (specific obligations, scope, addressees, thresholds) has not yet been determined and could accordingly not be researched. - Whether and when the consultation bill will actually become applicable law, and with what entry-into-force date, is open. No such deadline was found and none was invented. - Whether, alongside the horizontal bill, sector-specific AI requirements with their own legal character already exist (e.g. for AI in medical devices or in the financial sector) was not examined in this research. ### Sources - [Künstliche Intelligenz - Regulierung](https://www.bk.admin.ch/de/regulierung) — Bundeskanzlei (BK) / Bundesamt für Justiz (BJ), retrieved 2026-09-24 (behoerde) - [Künstliche Intelligenz](https://www.bk.admin.ch/de/ki) — Bundeskanzlei (BK), retrieved 2026-09-24 (behoerde) --- ## Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act) (CRA) *ID: `cra` · Type: verordnung · Scope: EU · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does CRA apply to you? The Cyber Resilience Act (Regulation (EU) 2024/2847) sets EU-wide, uniform cybersecurity requirements for hardware and software products with digital elements across their entire life cycle. Manufacturers must report actively exploited vulnerabilities and severe security incidents in stages - the reporting obligations have applied since 11 September 2026, with the regulation's full application from 11 December 2027. For Swiss manufacturers, the CRA applies as soon as they place products with digital elements on the EU market. Triggers in detail: - **If you manufacture products with embedded software** (confidence: wahrscheinlich): You state that you manufacture or distribute products with software or digital elements - the CRA requires cybersecurity by design and by default for such products across their entire product life cycle, as soon as they are placed on the EU market. - **If you act as a Manufacturer – provided that you manufacture products with embedded software** (confidence: pruefen): As a manufacturer of products with digital elements, you bear the main responsibility under the CRA for conformity assessment, reporting obligations and security updates - distributors and importers have lighter-touch obligations. For manufacturers without digital product components, the CRA does not apply. - **If you are active in the EU – provided that you manufacture products with embedded software** (confidence: pruefen): The CRA is triggered by placing a product on the EU market, not by the manufacturer's registered seat - if you offer your connectable products with digital elements in the EU, the CRA can apply regardless of your registered seat in Switzerland. Without digital product components, the EU market alone does not trigger the CRA. - **If you manufacture, import or distribute a medical device** (confidence: pruefen): For medical devices, the CRA generally does not apply; instead, the more specific cybersecurity requirements of the Medical Device Regulation (MDR) apply - check case by case whether your product falls under this CRA exemption. Exceptions: - Medical devices and in-vitro diagnostics already subject to Regulation (EU) 2017/745 or (EU) 2017/746. - Motor vehicles and vehicle parts with their own sector-specific type approval. - Aviation and marine equipment with their own sector-specific cybersecurity requirements. - Products developed exclusively for national security or military purposes. - Non-commercial open-source software developed and made available by volunteers without direct commercial intent - as soon as paid support or commercial integration into products sold is added, the exemption no longer applies. - Identical spare parts for products already placed on the market. ### Why **Does a Swiss software house without a physical product fall under the CRA?** Yes, potentially: the CRA covers not only hardware but also standalone software with digital elements that is placed on the EU market - for example apps or backend software that connects to devices or networks. What matters is placing it on the market in the EU, not the registered seat. **Is open-source software generally exempt from the CRA?** Only non-commercial open-source software developed and made available by volunteers without a profit motive. As soon as paid support, commercial distribution or integration into a product sold is added, the CRA applies as normal - open-source steward organisations have their own, lighter-touch obligations from December 2027. **How does the CRA relate to the EU Machinery Regulation?** Both frameworks require cybersecurity for connected products but cover different product categories: the CRA regulates products with digital elements in general, while the Machinery Regulation (EU) 2023/1230 specifically regulates machinery and its safety functions. For machinery with digital elements, it must be checked case by case which framework - or whether both - applies; see the separate norm file maschinenverordnung_2023_1230. ### Obligations - Secure-by-design and secure-by-default: consider cybersecurity from the start of development. - Draw up a declaration of conformity and apply CE marking for products with digital elements. - Report actively exploited vulnerabilities and severe security incidents via the central reporting platform (Single Reporting Platform) to the responsible CSIRT - early warning within 24 hours, detailed notification within 72 hours, final report within 14 days of remediation measures becoming available, or within one month for severe incidents. - Provide free security updates for at least 5 years or the expected product usage period. - Clearly indicate the end of the support period to customers. Deadlines: - 2026-06-11: Notifying authorities must have established the procedures for conformity assessment bodies. - 2026-09-11: Reporting obligations for manufacturers (actively exploited vulnerabilities, severe incidents) become applicable. - 2027-12-11: The Cyber Resilience Act applies in full, including conformity assessment obligations for all affected products. Penalties: According to secondary sources, breaches of the essential cybersecurity requirements can be penalised with fines of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher; the exact scale of fines by type of breach was not verified against the regulation's text itself in this session. ### Evidence - Technical documentation and declaration of conformity. - Evidence of the vulnerability management process. - Reporting logs via the CRA Single Reporting Platform or to ENISA. - Documented update and support period. Related to other norms in this knowledge base: maschinenverordnung_2023_1230, mdr. Not evidenced / open: - The EUR-Lex primary text of Regulation (EU) 2024/2847 (eur-lex.europa.eu/eli/reg/2024/2847/oj) could not be retrieved in this session (empty response); content evidenced via the EU Commission page digital-strategy.ec.europa.eu and the BSI, not via the regulation's text itself. - The exact date of entry into force of the regulation was not verified in this session and is therefore not listed. - The exact scale of fines by type of breach is evidenced only via a secondary source, not verified against the regulation's text. - Whether and how the open-source exemption exactly hinges on article text or a recital was not checked against the primary text. ### Sources - [Cyber Resilience Act – Reporting obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting) — Europäische Kommission (Generaldirektion CNECT), retrieved 2026-09-24 (behoerde) - [Cyber Resilience Act – Übersicht](https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html) — Bundesamt für Sicherheit in der Informationstechnik (BSI), retrieved 2026-09-24 (behoerde) - [Wichtigste Fragen & Antworten zum Cyber Resilience Act](https://www.cyber-regulierung.de/eu-cybersecurity-regulierung/cyber-resilience-act/faq/) — cyber-regulierung.de, retrieved 2026-09-24 (sekundaer) --- ## Digital Operational Resilience Act (Regulation (EU) 2022/2554) (DORA) *ID: `dora` · Type: verordnung · Scope: EU · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does DORA apply to you? DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers. The regulation has applied directly in the EU since 17 January 2025. For Swiss companies this is, per the client's assessment, a candidate not yet conclusively examined: relevant above all are Swiss financial institutions with an EU establishment, as well as Swiss ICT providers who supply financial entities in the EU/EEA. Triggers in detail: - **If your industry is Financial services** (confidence: pruefen): As a financial entity with an establishment, subsidiary or branch in the EU/EEA, that entity is directly subject to DORA's requirements on digital operational resilience. - **If you process payment transactions** (confidence: pruefen): If you process payment transactions for or with EU financial institutions, DORA may affect you indirectly - for example as an ICT third-party provider under the oversight framework for critical providers. This needs to be checked case by case. - **If you are active in the EU – provided that your industry is Financial services** (confidence: pruefen): If you provide services as a Swiss financial entity in the EU/EEA market, DORA can reach you via your customers' contractual requirements or via an EU establishment, even though not every detail of this was verified in the regulation's text itself in this research. - **If you are active in the EU – provided that you process payment transactions** (confidence: pruefen): If you provide services as a Swiss ICT or payment service provider (e.g. cloud, software, network, payment processing) for financial entities headquartered in the EU/EEA, DORA can reach you via your customers' contractual requirements, even without your own EU establishment. Exceptions: - According to the secondary sources examined, DORA is triggered by the financial entity's seat in the EU/EEA, not by the customer's seat - a Swiss financial entity without any EU establishment is accordingly not directly within scope. - A Swiss bank or insurer without a subsidiary, branch or licensed establishment in an EEA member state is, on this understanding, not directly covered; the finer points were not checked in the regulation's text itself (Art. 2), only via secondary sources. ### Why **Are we, as a Swiss fintech without an EU establishment, automatically exempt from DORA?** Based on the source status examined here, yes, as long as you have no EU/EEA establishment and are not classified as a critical ICT third-party provider for EU financial entities. A conclusive case-by-case review against the regulation's text (Art. 2 and Art. 31 DORA) was not carried out in this research. **Why is there no separate 'Finance' industry on the website yet?** That is a deliberate, still open decision by the client (see the architecture document, item 13). This norm file has been researched and evidenced; the decision to show DORA and the FINMA circular on the website as a separate industry is a separate, outstanding matter. ### Obligations - Establish an ICT risk management framework (per secondary sources, including governance, identification, protection, detection, response and recovery). - Report major ICT-related incidents to the competent supervisory authority. - Conduct regular digital operational resilience testing, for significant institutions including threat-led penetration testing (TLPT). - Manage ICT third-party risk, including contractual minimum requirements towards ICT providers. - For ICT third-party providers from third countries (such as Switzerland) classified as 'critical': per a secondary source, EU financial entities may only use their services if the provider has established a subsidiary in the EU/EEA within twelve months of classification - this statement was not verified against the regulation's text (Art. 31) itself. Deadlines: - 2025-01-17: DORA becomes binding and applicable in the EU/EEA (regulation in force since 17 January 2023, applicable from 17 January 2025 per the secondary sources examined). Penalties: The regulation's text itself (including Art. 50 on administrative sanctions) was not examined in full text in this research, as the EUR-Lex full text was not technically retrievable. Per secondary sources, national supervisory authorities can impose measures and sanctions on financial entities within the EU scope. For Swiss companies without their own EU scope, DORA, per the sources examined, does not act as directly enforceable, but primarily via EU customers' contractual requirements. ### Evidence - Documented ICT risk management framework. - Register of contracts with ICT third-party providers (per secondary sources part of DORA, not itself checked in the regulation's text). - Evidence of resilience tests carried out. - Reporting process for major ICT incidents. Related to other norms in this knowledge base: finma_rundschreiben, nis2. Not evidenced / open: - CANDIDATE STATUS: per the client's architecture decision, DORA has not yet been adopted into the website. No 'Finance' industry page exists yet; whether and how DORA applies to Swiss companies case by case has not yet been conclusively clarified (see ARCHITEKTUR-UND-CONTENT.md, item 13 and section 7.10). - The EUR-Lex full text of the regulation (in particular Art. 2 scope and Art. 31 oversight framework for critical ICT third-party providers) could not be technically retrieved in this research (JavaScript requirement of the EUR-Lex page). The statements on scope, third-country rules and sanctions come from secondary sources and are marked 'pruefen' accordingly. - The exact list of financial entity categories covered by DORA was taken not directly from the regulation's text but from secondary sources. - Whether and how FINMA-supervised institutions are additionally affected by DORA on top of existing FINMA requirements was not examined. ### Sources - [Verordnung (EU) 2022/2554 (DORA) – Übersichtsartikel](https://de.wikipedia.org/wiki/Verordnung_(EU)_2022/2554_(DORA)) — Wikipedia (Sekundärquelle, nicht die Verordnung selbst), retrieved 2026-09-24 (sekundaer) - [DORA und die Schweiz: Eine Analyse der EU-Verordnung und ihrer Auswirkungen auf Schweizer Unternehmen](https://www.lexcellence.swiss/de/dora-und-die-schweiz-eine-analyse-der-eu-verordnung-und-ihrer-auswirkungen-auf-schweizer-unternehmen/) — LEXcellence (Anwaltskanzlei, Sekundärquelle), retrieved 2026-09-24 (sekundaer) - [Regulation (EU) 2022/2554 (DORA) in the Official Journal of the EU](https://eur-lex.europa.eu/eli/reg/2022/2554/oj) — Amt für Veröffentlichungen der Europäischen Union (EUR-Lex), retrieved 2026-09-24 (primaer) --- ## General Data Protection Regulation (GDPR) *ID: `dsgvo` · Type: verordnung · Scope: EU · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does GDPR apply to you? The EU General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018 and governs the processing of personal data in the EU. Under the market-location principle in Article 3(2), it also covers Swiss companies that offer goods or services to people in the EU or monitor their behaviour - regardless of their own registered seat. Anyone covered generally has to appoint a representative in the EU under Article 27. Triggers in detail: - **If you are active in the EU** (confidence: pruefen): You state that you are active in the EU market - under Art. 3 GDPR, either an EU establishment is sufficient (Art. 3(1)) or, without an EU establishment, that you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2)). Whether there is deliberate targeting of the market or an occasional one-off sale without any GDPR relevance cannot be conclusively assessed from the market information alone and needs to be checked case by case. - **If you process customers' personal data – provided that you are active in the EU** (confidence: pruefen): You process personal data of customers and are active in the EU market - if this includes people in the EU to whom you specifically offer goods or services, or whose behaviour you monitor, the GDPR applies in addition to the FADP (Art. 3(2)). Without any EU market relevance, only the FADP obligations remain. - **If you process special category personal data – provided that you are active in the EU** (confidence: pruefen): You process special categories of personal data, for instance health data, and are active in the EU market - if this also concerns people in the EU, the GDPR's stricter requirements for precisely these data categories apply in addition to the FADP. Without any EU market relevance, only the FADP obligations remain. Exceptions: - The obligation to appoint a representative under Art. 27 does not apply if the processing is only occasional, does not include special categories of data (Art. 9) or data relating to criminal convictions (Art. 10) to any significant extent, and, taking into account the nature, scope and purpose of the processing, is unlikely to result in a risk to the rights and freedoms of data subjects (Art. 27(2)(a) GDPR). - The obligation to appoint a representative does not apply to public authorities and bodies (Art. 27(2)(b) GDPR). - Purely B2B offerings with no connection to natural persons in the EU do not trigger Art. 3(2) GDPR, as long as no personal data of people in the EU is processed. ### Why **Does a Swiss company without an EU establishment always need an EU representative?** No. The obligation under Art. 27 GDPR does not apply if the processing concerned is only occasional, does not concern special categories of data to any significant extent, and is unlikely to result in a risk to the rights and freedoms of data subjects, or if it concerns a public authority (Art. 27(2) GDPR). **Does the GDPR apply to a Swiss company that only occasionally sells goods to Germany?** What matters is not the individual export sale, but whether you specifically offer goods or services to people in the EU or monitor their behaviour (Art. 3(2) GDPR). An occasional sale without deliberate market targeting generally does not suffice for this. **How does the GDPR differ from the revised Swiss Federal Act on Data Protection (FADP)?** Both frameworks are structurally similar but differ in the level of fines, competent authorities and detailed requirements. Swiss companies with EU relevance under Art. 3(2) GDPR generally have to comply with both frameworks in parallel; see the separate norm file revdsg. ### Obligations - Be able to demonstrate a legal basis for every processing of personal data (Art. 6 GDPR). - Maintain a record of processing activities, unless an exemption applies (Art. 30 GDPR). - Be able to fulfil data subject rights: access, rectification, erasure, objection, data portability (Art. 12-22 GDPR). - Carry out a data protection impact assessment where processing is likely to result in a high risk (Art. 35 GDPR). - Report personal data breaches to the supervisory authority within 72 hours, and notify data subjects where required (Art. 33-34 GDPR). - Where Art. 3(2) applies: appoint in writing a representative in the EU, established in a member state where data subjects are located (Art. 27(1) and (3) GDPR). Deadlines: - 2018-05-25: The GDPR becomes applicable across the entire EU. Penalties: Fines under Art. 83 GDPR: up to EUR 10 million or 2% of total worldwide annual turnover of the preceding financial year for breaches under Art. 83(4) (e.g. against obligations on data processing or representative appointment), and up to EUR 20 million or 4% of total worldwide annual turnover for more serious breaches under Art. 83(5) (e.g. against basic processing principles, data subject rights, international data transfers) - whichever amount is higher. ### Evidence - Record of processing activities (Art. 30). - Documented legal bases and consents. - Data processing agreements with providers (Art. 28). - Evidence of the representative's appointment under Art. 27 (contact details, written appointment), where applicable. - Data protection impact assessments, where carried out. Related to other norms in this knowledge base: revdsg. Not evidenced / open: - The EUR-Lex primary text (eur-lex.europa.eu/eli/reg/2016/679/oj, also in the form legal-content/DE/TXT/... and .../PDF/...) was not retrievable in this session (empty or blocked response); the article wording was instead verified via the mirror dejure.org, not via the EDPB or EUR-Lex itself. - Whether and under what conditions individual Swiss bodies count as a 'public authority' within the meaning of Art. 27(2)(b) GDPR was not examined in depth. ### Sources - [Art. 27 DSGVO – Vertreter von nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeitern (Wortlaut-Spiegel)](https://dejure.org/gesetze/DSGVO/27.html) — dejure.org, retrieved 2026-09-24 (sekundaer) - [Art. 3 DSGVO – Räumlicher Anwendungsbereich (Wortlaut-Spiegel)](https://dejure.org/gesetze/DSGVO/3.html) — dejure.org, retrieved 2026-09-24 (sekundaer) - [Art. 83 DSGVO – Allgemeine Bedingungen für die Verhängung von Geldbussen (Wortlaut-Spiegel)](https://dejure.org/gesetze/DSGVO/83.html) — dejure.org, retrieved 2026-09-24 (sekundaer) --- ## EU regulations on information security in aviation (Part-IS) (Part-IS) *ID: `easa_partis` · Type: verordnung · Scope: EU, CH · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does Part-IS apply to you? Part-IS requires aviation organisations - from airports to airlines to air navigation services - to operate an information security management system (ISMS), which may be based on ISO/IEC 27001, together with risk management and reporting of security-relevant occurrences. The obligation applies in stages: from 16 October 2025 for airport operators, apron management services, and design and production organisations; from 22 February 2026 for airlines, maintenance organisations, CAMOs, training organisations and air navigation services. In Switzerland, Part-IS is implemented by FOCA; the exact legal anchoring via the Air Transport Agreement was not examined in the wording in this research. Triggers in detail: - **If your industry is Aviation** (confidence: wahrscheinlich): As an aviation organisation - for example an airport, airline, maintenance organisation, CAMO, training organisation or air navigation service provider - you generally fall under the Part-IS information security requirements once your type of organisation reaches the relevant deadline. - **If you operate critical infrastructure – provided that your industry is Aviation** (confidence: pruefen): If, as an aviation organisation, you also operate critical infrastructure in air transport (e.g. air navigation services, airport operations), this additionally falls under Part-IS - outside the aviation industry, 'critical infrastructure' alone does not trigger Part-IS, since it is not a general critical-infrastructure regulation. - **If you are active in Switzerland – provided that your industry is Aviation** (confidence: pruefen): For the Swiss market, FOCA implements Part-IS for aviation organisations; the exact legal transposition into the Air Transport Agreement was not examined in this research in the regulation's wording, only via FOCA's information pages. Outside the aviation industry, the Swiss market alone does not trigger Part-IS. Exceptions: - Organisations outside the categories named in the regulations (airport operators, apron management services, design/production organisations, air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers) are, per the source status examined, not directly covered. - A third regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified in this research only via a secondary source and was not examined for content - it therefore belongs under 'unsicher'. ### Why **Does our ISMS have to be certified to ISO/IEC 27001 to comply with Part-IS?** No. The FOCA page phrases it as an option for orientation ('may be based on ISO/IEC 27001'), not as a certification requirement. Whether certification is worthwhile case by case, or in practice expected by the regulator, was not conclusively clarified in this research and is marked 'pruefen'. **Does Part-IS apply to our Swiss company in the same way as in the EU?** FOCA implements Part-IS in Switzerland; the specific legal basis (transposition via the Air Transport Agreement) was not verified in the wording in this research, only via FOCA's information pages. A robust legal assessment in an individual case requires examining the Air Transport Agreement or consulting FOCA. ### Obligations - Establish and operate an information security management system (ISMS), which per FOCA may be based on ISO/IEC 27001. - Identify and assess information security risks with a potential impact on flight safety, and derive suitable measures. - Integrate the ISMS into the organisation's existing safety management system (SMS). - Train personnel on information security and monitor compliance with the requirements. - Report occurrences with an information-security dimension to the competent authority. Deadlines: - 2025-10-16: Part-IS applies to airport operators, apron management services, and design and production organisations (Delegated Regulation (EU) 2022/1645). - 2026-02-22: Part-IS applies to air carriers, maintenance organisations, CAMOs, approved training organisations (ATOs), aero-medical centres, operators of flight simulation training devices, ATCO training organisations, air navigation service providers, U-space service providers, as well as the competent supervisory authorities and EASA (Implementing Regulation (EU) 2023/203). Penalties: The FOCA and EASA pages examined do not state specific fines or sanction provisions for Part-IS. Per EASA, oversight is carried out via regular audits by the competent national authorities and EASA itself; at FOCA, a dedicated Information Security unit within the Protective Measures section has been responsible for this since 1 August 2024. Possible consequences of non-compliance (e.g. conditions or withdrawal of approvals) were not examined in the regulation's text itself as part of this research. ### Evidence - Documented ISMS with roles, responsibilities and a risk register. - Evidence of the ISMS's integration into the safety management system. - Training records for affected personnel. - Auditability towards FOCA or EASA as part of ongoing oversight (per the EASA source, monitoring takes place via 'regular audits'). Related to other norms in this knowledge base: iso27001, nis2. Not evidenced / open: - The legal transposition of Part-IS in Switzerland via the Air Transport Agreement was not examined in the regulation's wording or the agreement's annex, only via FOCA's information pages, which themselves do not state an explicit legal basis for the transposition. This corresponds to open item 8 in the website's architecture document ('Transposition into the Air Transport Agreement not read in the wording, only FOCA pages. Cross-check.'). - A third, more recent regulation on ground handling (Commission Delegated Regulation (EU) 2025/22) was identified only via a search result, not examined in full text. - Specific sanction or fine provisions for non-compliance were not researched in the regulation's text itself, only the statement on audits on the authorities' pages. - Whether there is a de facto certification expectation (rather than mere orientation towards ISO/IEC 27001) was not clarified. ### Sources - [EU-Verordnungen zur Informationssicherheit (Part-IS)](https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is) — Bundesamt für Zivilluftfahrt (BAZL), retrieved 2026-09-24 (behoerde) - [EU regulation on information security (Part-IS)](https://www.bazl.admin.ch/en/eu-regulation-on-information-security-part-is) — Bundesamt für Zivilluftfahrt (BAZL), retrieved 2026-09-24 (behoerde) - [IS — Information Security (Regulation Groups)](https://www.easa.europa.eu/en/regulation-groups/information-security) — European Union Aviation Safety Agency (EASA), retrieved 2026-09-24 (behoerde) --- ## Regulation laying down harmonised rules on artificial intelligence (EU AI Act) (EU AI Act) *ID: `eu_ai_act` · Type: verordnung · Scope: EU · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does EU AI Act apply to you? The EU AI Act (Regulation (EU) 2024/1689) regulates AI systems in stages by risk class and applies to providers and deployers whose AI systems are placed on the market in the EU or whose output is used there - regardless of registered seat. Bans on certain practices have applied since February 2025, rules for general-purpose AI models since August 2025, and transparency obligations since August 2026. The amending regulation (EU) 2026/1744 ('Digital Omnibus', published on 24 July 2026) has postponed the obligations for high-risk systems under Annex III to December 2027 and for AI in regulated products under Annex I to August 2028. Triggers in detail: - **If you provide AI systems** (confidence: wahrscheinlich): As the provider of an AI system placed on the market in the EU, you bear the most far-reaching obligations under the EU AI Act - from bans on certain practices to conformity assessment and transparency obligations, depending on your system's risk class. - **If you use AI systems** (confidence: pruefen): Even as a deployer - not only as a provider - of an AI system, you have obligations under the EU AI Act, in particular on transparency towards users and, for high-risk systems, on oversight and documentation. - **If you are active in the EU – provided that you use AI systems or provide AI systems** (confidence: pruefen): The EU AI Act is triggered by placing on the market or use in the EU, not by the registered seat - if you use AI systems whose output is used in the EU, the regulation can apply regardless of your seat in Switzerland. Without any use or provision of AI, the EU market alone does not trigger the regulation. Exceptions: - AI systems developed or used exclusively for military, defence or national security purposes. - Purely private, non-professional use of AI systems by natural persons. - Scientific research and development prior to market introduction. - Systems that, per the Digital Omnibus amendment (Regulation (EU) 2026/1744), serve exclusively user support, performance optimisation, automation or non-safety-relevant quality control no longer automatically fall under the high-risk classification. ### Why **What changed under Regulation (EU) 2026/1744 ('Digital Omnibus')?** The amending regulation, published on 24 July 2026, mainly postponed the deadlines for high-risk AI systems - to December 2027 for standalone high-risk systems (Annex III) and to August 2028 for AI in regulated products (Annex I). It also narrowed the definition of safety-relevant components and added two new bans. **Does the EU AI Act also apply to a Swiss company that only uses its own AI tool internally?** If the tool is used exclusively internally and without any EU connection, the AI Act generally does not apply. As soon as the system's output affects people in the EU or the system is placed on the market there, the provider or deployer obligations need to be checked. **From when must a high-risk AI system meet the full requirements?** For most high-risk applications under Annex III (e.g. personnel selection, creditworthiness assessment, biometric systems), the obligation applies, following the postponement by the Omnibus amendment, from 2 December 2027; for AI as a safety component in products already regulated (Annex I), from 2 August 2028. ### Obligations - Refrain from prohibited AI practices (including manipulative systems, social scoring, certain real-time remote biometric identification) since 2 February 2025; two further bans (including on non-consensual intimate content and abuse material) have applied since 2 December 2026. - For providers of general-purpose AI (GPAI) models: transparency and copyright obligations, plus additional risk assessments where there is systemic risk, since 2 August 2025. - Transparency obligations under Art. 50: labelling of AI-generated content, disclosure of interaction with an AI system, labelling of deepfakes and AI-generated text on matters of public interest - since 2 August 2026, with a four-month transition period for systems already on the market until 2 December 2026. - For high-risk AI systems under Annex III (including biometrics, critical infrastructure, education, employment, migration/asylum/border control): conformity assessment, risk management system, documentation, human oversight - applicable from 2 December 2027. - For high-risk AI as a safety component in regulated products under Annex I (e.g. lifts, toys): corresponding obligations from 2 August 2028. Deadlines: - 2025-02-02: Bans on certain AI practices and the obligation on AI literacy become applicable. - 2025-08-02: Rules for general-purpose AI (GPAI) models become applicable. - 2026-07-24: The amending regulation (EU) 2026/1744 ('Digital Omnibus') is published in the Official Journal. - 2026-08-02: Transparency obligations under Art. 50 become applicable. - 2026-12-02: The transition period for transparency obligations for systems already on the market ends; two further bans under Art. 5 enter into force. - 2027-12-02: Obligations for high-risk AI systems under Annex III become applicable (postponed from originally August 2026). - 2028-08-02: Obligations for high-risk AI as a safety component in regulated products under Annex I become applicable (postponed from originally August 2027). Penalties: Breaches of prohibited AI practices (Art. 5) can be penalised with fines of up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Breaches of transparency obligations under Art. 50 can be penalised with up to EUR 15 million or 3% of worldwide annual turnover. ### Evidence - Risk classification of the AI system (prohibited/high/limited/minimal) with justification. - Technical documentation and declaration of conformity for high-risk systems. - Labelling or disclosure under Art. 50 where transparency obligations apply. - Documentation of human oversight for high-risk use. Related to other norms in this knowledge base: ch_ki_regulierung, mdr. Not evidenced / open: - The EUR-Lex primary text of Regulation (EU) 2024/1689 and the amending regulation (EU) 2026/1744 could not be retrieved in this session (empty response, per prior findings HTTP 202/bot block); deadlines evidenced via the EU Commission page and a law-firm source, not via the regulation's text itself. - The exact entry-into-force date of Regulation (EU) 2026/1744 is given in a secondary source as '27 July 2026' (publication per prior findings on 24.7.2026) - not checked against the Official Journal itself. - The exact new wording of 'safety-relevant components' after the Omnibus amendment was not checked in full text. ### Sources - [Regulatory framework proposal on artificial intelligence](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) — Europäische Kommission (Generaldirektion CNECT), retrieved 2026-09-24 (behoerde) - [EU AI Act: Was ab dem 2. August 2026 gilt – und was verschoben wurde](https://www.fgs.de/news-and-insights/blog/detail/eu-ai-act-was-ab-dem-2-august-2026-gilt-und-was-verschoben-wurde) — Flick Gocke Schaumburg (Kanzlei), retrieved 2026-09-24 (sekundaer) --- ## FINMA Circular 2023/1 "Operational risks and resilience – banks" (FINMA Circular 2023/1) *ID: `finma_rundschreiben` · Type: branchenstandard · Scope: CH · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does FINMA Circular 2023/1 apply to you? FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management. It replaced the earlier Circular 2008/21. IMPORTANT: the title and content of this file come from secondary sources, not from a document examined in full text on finma.ch - the FINMA website could not be technically read in full text in this research. Before external use, the exact wording should be verified on finma.ch. Triggers in detail: - **If your industry is Financial services** (confidence: pruefen): If you are a bank or securities firm under the Swiss Banking Act, the FINMA circular on operational risks and resilience applies to you. For other financial institutions (insurers, asset managers), separate circulars exist that were not examined here. - **If you are active in Switzerland – provided that your industry is Financial services** (confidence: pruefen): As a FINMA-supervised institution operating in Switzerland, this circular may be relevant to you. Exceptions: - Per a secondary source, the primary addressees are banks under the Banking Act (BankA); for insurers, analogous requirements are said, per the same source, to apply under a separate circular (Circular 2017/02). Both statements were not verified on finma.ch itself. - Smaller institutions benefit, per a secondary source, from a simplified application differentiated by supervisory category; the exact design was not examined. ### Why **Is this circular already part of the public regulatory check on sacosi.ch?** No. Per the client's architecture decision, it is a candidate: there is no separate 'Finance' industry on the website yet, and inclusion is an open decision (see ARCHITEKTUR-UND-CONTENT.md, item 13). **Why does the information come from secondary sources instead of directly from finma.ch?** The FINMA website loads its circular overview dynamically via JavaScript/AJAX; direct full-text access was not technically possible with the tools available in this research. Before any external publication of this file, the exact wording should be checked on finma.ch. ### Obligations - Establish an integrated operational risk management framework. - Own ICT risk management with an inventory of critical data and processes. - Cyber risk management with threat intelligence and monitoring. - Business continuity management (BCM) including cyber resilience. - Definition and management of critical functions and critical data ('Critical Data'). Deadlines: - 2024-01-01: FINMA Circular 2023/1 entered into force per a secondary source (replacing Circular 2008/21); not verified on finma.ch itself. Penalties: The circular itself contains no penalty provisions of its own - per FINMA's own description of its supervisory practice (Art. 7(1)(b) FINMASA), FINMA circulars set out in detail the application of financial market legislation and bind FINMA in its application of the law. Breaches of the obligations set out in it can be addressed through FINMA's general supervisory instruments (rulings, measures); the exact instruments were not examined article by article in this research. ### Evidence - Documented operational risk framework. - ICT and cyber risk inventory. - BCM concept including cyber resilience measures. - Evidence of the management of critical functions towards FINMA as part of ongoing supervision. Related to other norms in this knowledge base: dora. Not evidenced / open: - CANDIDATE STATUS: as with DORA, per the client's architecture decision this circular has not yet been adopted into the website; no 'Finance' industry page exists. Applicability to individual CH companies has not been conclusively clarified (ARCHITEKTUR-UND-CONTENT.md, item 13). - The exact title 'Operational risks and resilience – banks', the entry-into-force date (1 January 2024) and the substantive key points come from a single secondary source (a consultancy), not from the circular itself on finma.ch. The FINMA circular overview page (https://www.finma.ch/de/dokumentation/rundschreiben/) was reached and confirms the general system of circulars, but delivers the specific list of current circulars only via a dynamic programming interface not readable in this research. - The statement on an analogous circular for insurers (Circular 2017/02) was not verified. - Whether the wording given in the brief, 'Operating risks and resilience – banks', or the wording found here, 'Operational risks and resilience – banks', is the correct official title must be checked directly on finma.ch before publication. ### Sources - [FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)](https://www.sidd.swiss/einblicke/finma-dora-leitfaden/) — SIDD Swiss (Beratungsunternehmen, Sekundärquelle), retrieved 2026-09-24 (sekundaer) - [Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)](https://www.finma.ch/de/dokumentation/rundschreiben/) — Eidgenössische Finanzmarktaufsicht (FINMA), retrieved 2026-09-24 (behoerde) --- ## Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431) and Code of Obligations, Art. 957–958f (duty to keep and retain accounts) (GeBüV / CO accounting) *ID: `gebuev_or` · Type: gesetz · Scope: CH · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does GeBüV / CO accounting apply to you? Anyone obliged to keep accounts under Art. 957 CO must retain business books, accounting records, the annual report and the auditor's report for ten years; the period begins at the end of the financial year (Art. 958f CO - checked in the wording). Retention on paper, electronically or in a comparable form is permitted, provided that conformity with the underlying business transactions is guaranteed and the records can be made legible again at any time. The details of keeping and retention are set out by the Federal Council, based on Art. 958f(4) CO, in the Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431). Triggers in detail: - **If you are active in Switzerland – provided that you are active in Switzerland** (confidence: sicher): If you keep your business books in Switzerland, you are subject - provided you are obliged to keep accounts under Art. 957 CO - to the retention obligations under the CO and the GeBüV. Exceptions: - Sole proprietorships and partnerships with revenue of less than CHF 500,000 in the last financial year only need to keep simplified accounts of income, expenses and assets ('milk-book accounting') under Art. 957(2) CO; the full accounting rules apply by analogy. This revenue threshold cannot be directly mapped with the regulatory check's 'groesse' input field (number of employees). - Associations and foundations not required to be entered in the commercial register, as well as foundations exempted from the audit requirement under Art. 83b(2) CC, are likewise subject only to the simplified accounting obligation under Art. 957(2) CO. ### Why **Is purely electronic retention sufficient, or do I also need paper?** Business books and accounting records may, per Art. 958f(3) CO, be retained on paper, electronically or in a comparable manner - there is no paper requirement for this. The annual report and the auditor's report, however, must be retained in writing and signed, per Art. 958f(2) CO. **From when does the ten-year period run?** The retention period begins at the end of the financial year to which the records relate (Art. 958f(1) CO). **Where do I find the detailed technical requirements for electronic retention?** These are set out by the Federal Council, based on Art. 958f(4) CO, in the Ordinance on the Keeping and Retention of Accounting Records (GeBüV, SR 221.431). The GeBüV text itself was not technically retrievable in full text in this research; it should be consulted directly before making a binding statement on specific requirements. ### Obligations - Keep accounts in accordance with the principles of proper accounting: complete, accurate and systematic recording of business transactions, documentary evidence for every entry, clarity, appropriateness and verifiability (Art. 957a CO). - Retain business books, accounting records, the annual report and the auditor's report for ten years; the period begins at the end of the financial year (Art. 958f(1) CO). - The annual report and the auditor's report must be retained in writing and signed (Art. 958f(2) CO). - Business books and accounting records may be retained on paper, electronically or in a comparable manner, provided that conformity with the underlying business transactions and facts is guaranteed and the records can be made legible again at any time (Art. 958f(3) CO). - Any written record on paper, electronically or in a comparable form that is needed to trace the underlying business transaction counts as an accounting record (Art. 957a(3) CO). Penalties: A breach of the duty to keep accounts or retain records can carry criminal consequences (e.g. in case of bankruptcy); the exact wording of the relevant penal provision was not examined in full text in this research and is therefore not cited with an article number. Under civil law, deficient accounting can also considerably worsen a company's evidentiary position (e.g. in disputes or a tax audit). ### Evidence - Complete documentary records with traceability of every entry. - Demonstrable retention over the full ten-year period from the end of the relevant financial year. - For electronic retention: evidence of conformity with the original transactions and the ability to make records legible at any time - the specific technical requirements (traceability, integrity, availability) are set out in the GeBüV; the GeBüV ordinance text itself could not be technically retrieved in full text in this research, so the principles are evidenced only via a secondary source (a Wikipedia summary) and noted under 'unsicher'. Related to other norms in this knowledge base: gobd, revdsg. Not evidenced / open: - The ordinance text of the Ordinance on the Keeping and Retention of Accounting Records itself (SR 221.431) could not be technically retrieved in full text from fedlex.admin.ch in this research (the page requires JavaScript; several direct document download paths were checked without success). All statements on the GeBüV's content come from a Wikipedia summary (SR number 221.431, enactment date 24 April 2002, entry into force 1 June 2002, last major amendment 1 January 2013) and are marked as secondary accordingly. - Specific GeBüV article numbers on the traceability, integrity and availability of electronic retention were NOT verified in the ordinance's text and are therefore deliberately not cited with an article number. - The revenue threshold of CHF 500,000 (Art. 957(2) CO) cannot be mapped in the regulatory check's vocabulary, since the 'groesse' field captures the number of employees, not revenue - a trigger based on the revenue threshold was therefore deliberately not formulated. - The exact criminal sanction provision for breach of the accounting duty was not examined in full text and is therefore described without an article number. ### Sources - [Bundesgesetz betreffend die Ergänzung des Schweizerischen Zivilgesetzbuches (Fünfter Teil: Obligationenrecht), SR 220 – konsolidierte Fassung, Art. 957, 957a, 958f](https://www.fedlex.admin.ch/eli/cc/27/317_321_377/de) — Bundeskanzlei / Fedlex, Systematische Rechtssammlung des Bundes, retrieved 2026-09-24 (primaer) - [Geschäftsbücherverordnung (GeBüV) – Übersichtsartikel (SR-Nummer, Erlassdatum, Struktur der Verordnung)](https://de.wikipedia.org/wiki/Gesch%C3%A4ftsb%C3%BCcherverordnung) — Wikipedia (Sekundärquelle, nicht die Verordnung selbst), retrieved 2026-09-24 (sekundaer) --- ## Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD) (GoBD) *ID: `gobd` · Type: verordnung · Scope: DE · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does GoBD apply to you? The GoBD is an administrative circular of the German Federal Ministry of Finance (BMF) that sets out in detail how books, records and electronic documents are to be kept properly, recorded immutably and retained under the Fiscal Code (Sections 146 f. AO), together with requirements on procedural documentation and the tax authorities' data access. It is relevant to you if you are obliged to keep books or records in Germany - for example via a German subsidiary, permanent establishment or your own business activity in Germany. Retention periods under Section 147 AO were checked in full text: 10 years for books, records, inventories, annual financial statements and customs documents, 8 years for accounting records, 6 years for commercial and business correspondence. Triggers in detail: - **If you are active in Germany – provided that you are active in Germany** (confidence: wahrscheinlich): If you conduct business in Germany - for example through a German subsidiary or permanent establishment - you must align your electronic bookkeeping and retention with the GoBD and Sections 146 f. AO. Exceptions: - Per a secondary source, the GoBD is addressed to everyone obliged to keep books or records under German tax law - not only to companies obliged to keep accounts under commercial law in the classic sense. The exact scope of addressees was not examined in the BMF circular itself, only via a secondary source. - Whether and to what extent a Swiss company without a German permanent establishment or subsidiary can be affected (e.g. when registering for German VAT purposes) was not clarified in this research. ### Why **Does the GoBD also apply to our Swiss parent company, or only to the German subsidiary?** The GoBD is tied to the German duty to keep books and records under Sections 146 f. AO. For a purely Swiss parent company without a German permanent establishment or subsidiary, applicability was not clarified in this research; what generally matters is the tax liability of the respective German entity. **How long do I have to retain accounting records in Germany - 10 years as in Switzerland?** No, not identical: under Section 147(1) AO, a period of 8 years applies to accounting records in Germany, while books and records themselves must be retained for 10 years. This differs from the Swiss rule under Art. 958f CO, where a uniform 10-year period applies to business books and accounting records (see the norm file gebuev_or). **Is electronic archiving sufficient if the accounting runs abroad?** Within the EU, relocating electronic bookkeeping is permissible provided the German tax authority's data access remains guaranteed. For third countries such as Switzerland, prior written approval of the tax authority is required under Section 146(2a) AO, combined with further conditions. ### Obligations - Individual, complete, accurate, timely and orderly recording of entries and other required records; for cash register systems, ongoing (typically daily) cash records are required (Section 146(1) AO, checked in full text). - Immutability: changes to entries or records may not be made in a way that the original content is no longer ascertainable; ambiguous changes in substance are also inadmissible (Section 146(4) AO, checked in full text). - For electronic storage: data must be available at all times during the entire retention period and be made legible without delay (Section 146(5) AO, checked in full text); under Section 147(2) AO, electronic documents subject to retention must additionally be machine-evaluable (checked in full text). - Relocating electronic bookkeeping abroad: permissible within the EU, provided the tax authority's data access is guaranteed; in third countries only with written approval of the tax authority under further conditions (Section 146(2a) f. AO, checked in full text). - Retention under Section 147(1) AO: books, records, inventories, annual financial statements and management reports as well as customs documents for 10 years; accounting records for 8 years; commercial or business correspondence received and sent, and other documents, for 6 years (checked in full text). - Start of the period under Section 147(4) AO: at the end of the calendar year in which the last entry was made in the book or record (checked in full text). - Maintain procedural documentation that makes the GoBD-compliant course of data processing traceable (per secondary sources, a core GoBD component; not examined in full text in the BMF circular itself). - Enable the tax authority's data access as part of a field audit, including machine evaluation or provision in evaluable formats (Section 147(6) AO, checked in full text). Deadlines: - 2019-11-28: Revised version of the GoBD circular (reference number per a secondary source IV A 4 - S 0316/19/10003), in force from 1 January 2020 - date verified not in the BMF circular itself but only via a secondary source (Wikipedia). - 2024-03-11: First known amendment of the GoBD circular (reference number per a secondary source IV D 2 - S 0316/21/10001:002) - not verified in the BMF circular itself. - 2025-07-14: Further amendment, per a secondary source with a focus on electronic invoices - not verified in the BMF circular itself. Penalties: Checked in full text is the sanction under Section 146(2c) AO: for breaches of the requirements on relocating electronic bookkeeping abroad, the tax authority can impose a delay penalty of EUR 2,500 to 250,000. Further consequences of improper bookkeeping (e.g. estimation of the tax base) are possible under the general understanding of German tax law, but were not verified in the statutory text (e.g. Section 162 AO) in this research and are therefore noted under 'unsicher'. ### Evidence - Procedural documentation on the IT systems and processes used (content not examined in full text in the BMF circular). - Evidence of the immutability of electronic records (e.g. via audit-proof archiving systems). - Complete documentary records retained within the deadlines under Section 147(1) and (3) AO. - Readiness for the tax authority's data access (Z1 direct access, Z2 indirect access, Z3 provision of data carriers) - these types of access are generally known GoBD terminology but were not verified in the BMF circular itself in full text in this research and are therefore noted under 'unsicher'. Related to other norms in this knowledge base: gebuev_or. Not evidenced / open: - The actual BMF circular on the GoBD (full text) could not be technically retrieved in this research: bundesfinanzministerium.de is protected by a bot-management system (Radware/perfdrive) that blocks automated access; archived Wayback Machine copies also returned only 404 error pages. All statements on procedural documentation, the types of data access (Z1/Z2/Z3) and the exact reference numbers/dates of the amendment circulars come from a single secondary source (Wikipedia) and are marked accordingly. - The existence and content of the data access types Z1 (direct access), Z2 (indirect access) and Z3 (provision of data carriers) are generally known GoBD terminology but were not verified in the BMF circular itself in this research. - Whether an even more current version exists beyond the three amendment circulars named (2019, 2024, 2025) was not examined. - Sanction consequences for improper bookkeeping beyond the Section 146(2c) AO provision checked in full text (e.g. the power of estimation under Section 162 AO) were not verified. ### Sources - [§ 146 AO – Ordnungsvorschriften für die Buchführung und für Aufzeichnungen](https://www.gesetze-im-internet.de/ao_1977/__146.html) — Bundesministerium der Justiz / gesetze-im-internet.de, retrieved 2026-09-24 (primaer) - [§ 147 AO – Ordnungsvorschriften für die Aufbewahrung von Unterlagen](https://www.gesetze-im-internet.de/ao_1977/__147.html) — Bundesministerium der Justiz / gesetze-im-internet.de, retrieved 2026-09-24 (primaer) - [GoBD – Übersichtsartikel (Datierung der BMF-Schreiben und Änderungen)](https://de.wikipedia.org/wiki/Grunds%C3%A4tze_zur_ordnungsm%C3%A4%C3%9Figen_F%C3%BChrung_und_Aufbewahrung_von_B%C3%BCchern,_Aufzeichnungen_und_Unterlagen_in_elektronischer_Form_sowie_zum_Datenzugriff) — Wikipedia (Sekundärquelle, nicht das BMF-Schreiben selbst), retrieved 2026-09-24 (sekundaer) --- ## IEC 62304 – Medical device software – Software life cycle processes (IEC 62304) *ID: `iec62304` · Type: norm · Scope: CH, EU, DE · Basis of obligation: marktgetrieben · As of: 2026-09-24* ### When does IEC 62304 apply to you? IEC 62304 sets out how you must safely develop and maintain software for medical devices across the entire life cycle - planning, requirements, architecture, implementation, verification, release, maintenance. It assigns your software to one of three safety classes (A, B or C) based on the risk to patients, users or third parties and, as the recognised 'state of the art', is the accepted basis for meeting the software requirements of the EU MDR and the Swiss MedDO. Triggers in detail: - **If you manufacture products with embedded software – provided that you manufacture, import or distribute a medical device** (confidence: wahrscheinlich): You develop products with software, including a medical device - if this software is part of the medical device or itself qualifies as a medical device, IEC 62304 prescribes the software life cycle process, including risk classification (A/B/C) and documentation obligations. For software outside medical devices, IEC 62304 does not apply. - **If you manufacture, import or distribute a medical device** (confidence: pruefen): IEC 62304 only applies to the extent your medical device contains software or is itself software - check whether this condition applies to your specific product. - **If your industry is MedTech** (confidence: pruefen): As a MedTech company with a software component in your products, IEC 62304 is highly likely to be relevant to you; without a specific software element in the product, the standard does not apply. Exceptions: - Purely hardware medical devices with no software component fall outside the standard's scope. - For products already in the field classified as 'legacy software', adapted evidence requirements apply in practice (a retrospective approach), the exact criteria for which were not verified in this session. ### Why **What distinguishes safety classes A, B and C?** The classification depends on the possible harm from a software failure: broadly, class A applies to software where no injury or damage to health is possible, class B to software where a non-serious injury is possible, and class C to software where death or serious injury is possible. The exact, standard-conformant definition of the three classes was not verified word-for-word from a source read in this session (see 'unsicher') and should be checked against the standard itself before any binding classification. **Is IEC 62304 alone sufficient for the conformity of our medical device software?** No. IEC 62304 covers the software life cycle but does not replace the overarching risk management (for which ISO 14971 is the accepted basis in practice) or the quality management system under ISO 13485, into which the software processes must be embedded. **Is the currently valid version of IEC 62304 up to date?** The most recently consolidated, internationally valid version is IEC 62304:2006 with Amendment 1:2015 (sometimes referred to as Edition 1.1). A second edition is, per secondary sources, in preparation but had not yet been published as of this research. ### Obligations - Determine the software safety class (A, B or C) on a risk basis before development begins, or again if the risk context changes. - Draw up a software development plan covering the processes of planning, requirements analysis, architectural design, detailed design, implementation, integration and system testing, and release. - Document requirements and architecture in a risk-oriented manner and link them to safety aspects and - increasingly, in revised practice - security aspects. - Operate configuration management and a problem-resolution process for the entire service life of the software, including after market launch (software maintenance process). - Scale verification and testing activities to the risk of the respective class; higher classes require more extensive evidence. Penalties: IEC 62304 is a technical standard with no penalties of its own. Since it is used as the state of the art for the software requirements of the EU MDR and the Swiss MedDO, non-compliance in practice leads to audit findings, refusal of CE marking or Swissmedic authorisation, and, in the event of harm, a weaker position in product liability. ### Evidence - Software development plan. - Software requirements specification and architecture documentation. - Evidence of verification, integration and system testing, class-dependent in each case. - Configuration management records. - Documented software maintenance and problem-resolution process. - As part of MDR/MedDO conformity assessment: embedding this evidence in the technical documentation of the overall product. Related to other norms in this knowledge base: mdr, mepv, iso13485. Not evidenced / open: - The full text of IEC 62304 is paywalled and could not be read in this session; the specific catalogue/publication page on webstore.iec.ch also could not be reliably located (the search function only returns results via JavaScript, and guessed publication IDs led to incorrect, unrelated documents). The URL cited is the general IEC webstore homepage, not a verified direct page for IEC 62304. - The exact, standard-conformant wording defining safety classes A/B/C (in particular the phrasing 'no injury or damage to health', 'non-serious injury', 'death or serious injury') was not quoted word-for-word from a source read in this session, but reproduced from established professional knowledge. This should be checked against the standard's text before any binding classification as part of the regulatory check. - The exact status and expected publication date of a second IEC 62304 edition were only sketched via a secondary source (Johner Institut) and not verified; for current compliance practice, the 2006+AMD1:2015 version is authoritative regardless. - A specific Swissmedic reference to IEC 62304 (e.g. its own guideline) could not be found in this session (the presumed Swissmedic page on medical software returned HTTP 404). ### Sources - [IEC 62304:2006+AMD1:2015 – Medical device software – Software life cycle processes](https://webstore.iec.ch/) — International Electrotechnical Commission (IEC), retrieved 2026-09-24 (sekundaer) - [IEC 62304 – Software-Lebenszyklus für Medizinprodukte (Blog)](https://www.johner-institut.de/blog/regulatory-affairs/iec-62304/) — Johner Institut, retrieved 2026-09-24 (sekundaer) --- ## IEC 62443 — Industrial communication networks, network and system security (IEC 62443) *ID: `iec62443` · Type: norm · Scope: CH, EU, DE · Basis of obligation: freiwillig · As of: 2026-09-24* ### When does IEC 62443 apply to you? IEC 62443 is the international standards series for cybersecurity in industrial automation and control systems (OT/ICS). It is voluntary to apply but is increasingly used as an accepted benchmark for OT security, for example in the context of NIS2 implementation and the Cyber Resilience Act. The series distinguishes requirements for operators (Part 2-1), technical system requirements with four security levels (Part 3-3), and requirements for manufacturers of components (Parts 4-1 and 4-2); certification is possible but not uniformly mandated. Triggers in detail: - **If you operate OT (operational technology) plant** (confidence: sicher): Anyone operating operational technology (OT) or industrial control systems finds in IEC 62443 the internationally recognised framework for systematically building and demonstrating their cybersecurity. - **If your industry is Energy** (confidence: pruefen): In energy supply, IEC 62443 is increasingly used as an accepted state of the art for securing control systems, complementing the ICT minimum standard under the Electricity Supply Ordinance. - **If your industry is Manufacturing** (confidence: wahrscheinlich): In manufacturing, IEC 62443 links requirements for operators (62443-2-1) with those for manufacturers of connected components (62443-4-1/4-2) and is increasingly accepted by customers and auditors as evidence of OT security. - **If you operate critical infrastructure** (confidence: pruefen): Operators of critical infrastructure are required by legislation such as NIS2 implementation to take appropriate technical measures; IEC 62443 is, in practice, regarded as an accepted way of giving concrete effect to this obligation for OT environments, even though the law does not name the standard in its wording. - **If you act as a Manufacturer** (confidence: pruefen): Manufacturers of components for industrial control systems are increasingly asked by operators for a development process under IEC 62443-4-1 and components under 62443-4-2. Exceptions: - There is no legal obligation to be certified to IEC 62443 in Switzerland or the EU; the standards series as a whole is voluntary to apply. - Pure office IT with no connection to production or control systems falls outside the series' scope. ### Why **Is IEC 62443 legally required?** No, the standards series is voluntary. Laws such as NIS2 implementation or the Cyber Resilience Act require appropriate technical measures without naming IEC 62443 in their wording; in practice, however, the series is regarded as the accepted benchmark that such measures for OT environments are based on. **What is the difference between parts 2-1, 3-3 and 4-1/4-2?** 62443-2-1 is addressed to operators and describes a security programme for the OT environment. 62443-3-3 sets technical system requirements and security levels (SL1 to SL4). 62443-4-1 and 62443-4-2 are addressed to manufacturers: 4-1 to the development process, 4-2 to the technical properties of the individual component. **What do security levels SL1 to SL4 mean?** They describe resilience against increasingly capable attackers: SL1 protects against occasional, non-malicious misuse, SL2 against targeted attacks with simple means, SL3 against attacks with considerable effort and expertise, SL4 against attacks with very high effort, for example by state actors. ### Obligations - For operators (IEC 62443-2-1, 2024 edition): build a security programme for the OT environment with a four-stage maturity model (Initial, Managed, Defined, Improving), explicitly aligned with ISO/IEC 27001 to avoid duplicating work with an existing ISMS - For system design (IEC 62443-3-2, 3-3): risk assessment, a zones-and-conduits model, and defining a security level (SL1 to SL4) per zone - For manufacturers (IEC 62443-4-1): a secure development process across the entire product life cycle - For component manufacturers (IEC 62443-4-2): technical security requirements per component type (embedded devices, network components, host components, software applications) Penalties: No fine from the standard itself, since it is voluntary; in practice: without documented implementation, auditors, cyber insurers and customers may object that the 'state of the art' for OT security has not been reached, which can make tenders and taking out cyber insurance more difficult. ### Evidence - Conformity assessment/certification by specialised certification bodies is possible but not uniformly mandated - Documented risk assessment, zones/conduits model and assigned security level as an internal evidence document - For manufacturers: evidence of a secure development process (62443-4-1) and product conformity (62443-4-2), partly via manufacturer declaration, partly via certification by a testing body Related to other norms in this knowledge base: iso27001, ikt_minimalstandard_stromvv, nis2, cra. Not evidenced / open: - iec.ch (main site/blog) was unreachable in this session (HTTP 403); only the IEC webstore entry for part 1-1 (publication metadata, not the full text of the standard) could be read directly. - A literal reference to IEC 62443 in NIS2 implementation or the Cyber Resilience Act was not found in a statutory text in this session; the classification as 'accepted state of the art' rests on secondary sources and professional knowledge, not on a legal reference checked directly. - The complete list of all published parts of the series (in particular 2-2, 2-3, 2-4, 3-1) was only checked via secondary sources (Fortinet, Wikipedia), not individually verified in the IEC webstore. - Whether and which accredited certification bodies in Switzerland offer IEC 62443 certifications was not examined in this session. ### Sources - [IEC TS 62443-1-1:2009 — Terminology, concepts and models](https://webstore.iec.ch/en/publication/7029) — IEC (International Electrotechnical Commission), retrieved 2026-09-24 (sekundaer) - [IEC 62443](https://en.wikipedia.org/wiki/IEC_62443) — Wikipedia (Übersichtsartikel), retrieved 2026-09-24 (sekundaer) - [IEC 62443 Standard: Industrial Cybersecurity Framework Explained](https://www.fortinet.com/resources/cyberglossary/iec-62443) — Fortinet, retrieved 2026-09-24 (sekundaer) - [What Are ISO/IEC 62443-4-1 and 62443-4-2?](https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/) — Security Compass (Suchergebnis), retrieved 2026-09-24 (sekundaer) --- ## ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a) (ICT Minimum Standard (StromVV)) *ID: `ikt_minimalstandard_stromvv` · Type: verordnung · Scope: CH · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does ICT Minimum Standard (StromVV) apply to you? Since 1 July 2024, the recommendations of the Minimum Standard for Improving ICT Resilience (ICT Minimum Standard, May 2023 edition) have been binding, per the respective protection level under Annex 1a, under Art. 5a of the Electricity Supply Ordinance (StromVV, SR 734.71) for grid operators, for generators and storage operators with a total of 100 MW or more of controllable capacity via a single system, and for service providers able to permanently remote-control such installations. The Swiss Federal Electricity Commission (ElCom) can demand proof of the protection level being reached at any time. Triggers in detail: - **If your industry is Energy** (confidence: wahrscheinlich): As a company in the energy industry, you are in principle a candidate as a grid operator, generator or storage operator under Art. 5a StromVV - whether you are specifically covered depends on your role and, for generation or storage, on the 100 MW threshold of controllable installed capacity. - **If you operate critical infrastructure – provided that your industry is Energy** (confidence: wahrscheinlich): As an energy company, you count among critical infrastructure - in the energy sector, Art. 5a StromVV precisely narrows the circle of those obliged to grid operators, larger generators/storage operators of 100 MW or more, and their remote-control service providers; check whether you fall into one of these three categories. Critical infrastructure outside the energy industry does not fall under this ordinance. - **If you operate OT (operational technology) plant – provided that your industry is Energy** (confidence: wahrscheinlich): You operate or control OT installations (operational technology) in the energy sector - if these serve electricity generation, storage or grid operation, or you can permanently remote-control such installations for third parties, the ICT Minimum Standard under Art. 5a StromVV may apply to you. OT installations outside the energy industry are not covered. - **If you act as a Operator – provided that your industry is Energy** (confidence: pruefen): As the operator of an installation in the energy sector, you should check case by case whether you fall under one of the three categories named in Art. 5a(1) StromVV: grid operator, generator/storage operator with 100 MW or more (except nuclear power plants), or a service provider with permanent remote-control access to such installations. Exceptions: - Operators of nuclear power plants are expressly exempted from the obligations for generators under Art. 5a(1)(b) StromVV; they are subject to their own nuclear-energy-law safety requirements. - Generators and storage operators whose installations together have less than 100 MW of capacity, or which cannot be controlled via a single system, are not covered under Art. 5a(1)(b) StromVV. - The internationally recognised standards named within the ICT Minimum Standard itself are not binding on their own (Art. 5a(2) StromVV); what is binding are the ICT Minimum Standard's recommendations, even where these refer to such standards. ### Why **What exactly is the ICT Minimum Standard?** A catalogue of recommendations for improving ICT resilience (May 2023 edition). Per the footnote to Art. 5a StromVV, it is available free of charge from the Federal Office for National Economic Supply (FONES) via www.bwl.admin.ch or by email to info@bwl.admin.ch. Art. 5a StromVV declares its recommendations binding for certain electricity-supply actors, depending on the protection level. **Who determines which protection level (A, B, C) applies to my company?** The assignment is made under Annex 1a StromVV. The exact assignment criteria were not examined in the full text of Annex 1a in this research; only the general three-tier structure is known from a professional source (see unsicher). **Is the ICT Minimum Standard the same as an NCSC document?** No. The ordinance text itself (footnote 27 to Art. 5a StromVV) refers to the Federal Office for National Economic Supply (FONES) as the source, not to the NCSC/BACS. This attribution, taken directly from the ordinance's text, differs from an originally assumed NCSC responsibility. ### Obligations - Implement the recommendations of the ICT Minimum Standard (May 2023 edition) according to the protection level assigned to one's own role or installation under Annex 1a StromVV (Art. 5a(1) StromVV). - Demonstrate to ElCom, on request, that the respective protection level has been reached (Art. 5a(3) StromVV). Deadlines: - 2024-07-01: Art. 5a StromVV (protection against cyber threats / ICT Minimum Standard) enters into force (AS 2024 282). Penalties: Art. 5a StromVV itself does not provide for a penalty provision of its own. ElCom can demand proof of the protection level being reached at any time (Art. 5a(3) StromVV) and order measures as part of its general supervisory and directive powers under the Electricity Supply Act (StromVG). A specifically quantified sanction provision for non-compliance with the ICT Minimum Standard could not be found in the ordinance text read (see unsicher). ### Evidence - Evidence documentation on the protection level reached (A, B or C) towards ElCom. - Documentation of the implementation of the individual ICT Minimum Standard recommendations per assigned protection level (Annex 1a StromVV). Related to other norms in this knowledge base: isg_meldepflicht, nis2. Not evidenced / open: - The exact assignment criteria for protection levels A, B and C to individual company categories (Annex 1a StromVV) were not read in full text; the classification 'A = most important companies, B = medium-sized, C = smaller actors' comes from a professional article (InfoGuard, secondary), not directly from the ordinance's text. - Per the footnote to Art. 5a StromVV, the ICT Minimum Standard is obtained via the Federal Office for National Economic Supply (FONES, www.bwl.admin.ch); a responsibility of ncsc.admin.ch for this specific document was not confirmed in this research. - A specific sanction provision for breaches of Art. 5a StromVV was not found; whether and how ElCom sanctions breaches case by case (e.g. based on the StromVG) was not researched. ### Sources - [Stromversorgungsverordnung (StromVV), SR 734.71, Art. 5a Schutz vor Cyberbedrohungen (konsolidierter Stand am 1. Januar 2025, Art. 5a eingefügt durch Änderung vom 31. Mai 2024, in Kraft seit 1. Juli 2024)](https://www.fedlex.admin.ch/eli/oc/2024/282/de) — Bundeskanzlei / Fedlex (Änderungserlass AS 2024 282, wirksam in der konsolidierten StromVV SR 734.71), retrieved 2026-09-24 (primaer) - [IKT-Minimalstandards nach StromVV: So vermeiden Sie ein Blackout-Szenario](https://www.infoguard.ch/de/blog/ikt-minimalstandards-nach-stromvv) — InfoGuard AG (Fachartikel), retrieved 2026-09-24 (sekundaer) --- ## Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG) (ISG reporting obligation) *ID: `isg_meldepflicht` · Type: gesetz · Scope: CH · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does ISG reporting obligation apply to you? Since 1 April 2025, the authorities and organisations individually listed in Art. 74b of the Information Security Act (ISG, SR 128) must report cyberattacks on their IT resources to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery (Art. 74a and 74e ISG). Covered are 21 categories of critical infrastructure named in the act, from universities and energy suppliers to banks and hospitals to cloud providers headquartered in Switzerland; the Federal Council can exempt bodies with only minor impact from the reporting obligation (Art. 74c ISG). Triggers in detail: - **If you operate critical infrastructure** (confidence: wahrscheinlich): You operate or manage critical infrastructure - Art. 74b ISG lists 21 categories of authorities and companies for this; if you are covered, you must report cyberattacks to BACS within 24 hours, unless an exemption under Art. 74c ISG applies. - **If your industry is Energy** (confidence: wahrscheinlich): Companies active in energy generation, trading, metering or control under the Energy Act belong to the reporting categories expressly named in Art. 74b(1)(d) ISG - the only exemption is for holders of licences under the Nuclear Energy Act. - **If your industry is Financial services** (confidence: sicher): Companies subject to the Banking Act, the Insurance Supervision Act or the Financial Market Infrastructure Act are named individually as subject to the reporting obligation under Art. 74b(1)(e) ISG. - **If your industry is Healthcare** (confidence: pruefen): Healthcare institutions listed on a cantonal hospital list, as well as approved medical laboratories, fall under Art. 74b(1)(f-g) ISG; you should check case by case whether your specific institution is on a hospital list or holds a corresponding laboratory licence. - **If your industry is Software/SaaS** (confidence: pruefen): If you provide cloud computing, search engines, digital security or trust services, or data centres headquartered in Switzerland, you belong to the reporting providers named in Art. 74b(1)(t) ISG - this does not apply to every software/SaaS company. Exceptions: - The Federal Council exempts authorities and organisations from the reporting obligation if malfunctions triggered by cyberattacks have only minor effects on the functioning of the economy or the wellbeing of the population (Art. 74c ISG). - If a body subject to the reporting obligation also carries out activities not covered by Art. 74b(1) ISG, there is no reporting obligation for cyberattacks that affect exclusively those other activities (Art. 74b(2) ISG). ### Why **Who exactly is subject to the reporting obligation?** Art. 74b(1) ISG lists 21 categories (letters a-u) by name: universities; federal, cantonal and municipal authorities as well as inter-cantonal/municipal organisations; organisations with tasks in security/rescue, drinking water supply, wastewater treatment, waste disposal; companies in energy generation/trading/metering/control (except nuclear power plant licence holders); companies under the Banking Act, the Insurance Supervision Act or the Financial Market Infrastructure Act; healthcare institutions on cantonal hospital lists; approved medical laboratories; companies with a medicinal product licence; social insurance organisations; the Swiss Broadcasting Corporation; news agencies of national significance; registered postal service providers; railway, cable-car, trolleybus, bus and shipping companies with a concession; civil aviation companies; companies under the Maritime Navigation Act; companies for essential goods; registered telecommunications service providers; registrars/registry operators of internet domains; providers of services for exercising political rights; providers of cloud computing, search engines, digital security/trust services and data centres headquartered in Switzerland; and manufacturers of hardware/software able to remotely maintain critical infrastructure. **From when does the 24-hour deadline run?** From the discovery of the cyberattack by the reporting authority or organisation (Art. 74e(1) ISG). If information is still missing at that point, the report must be supplemented as soon as new information becomes available (Art. 74e(3) ISG). **What does BACS do with the reported data?** Per Art. 74a(4) ISG, the reporting obligation serves exclusively to enable BACS to detect attack patterns on critical infrastructure at an early stage, warn other potentially affected parties, and recommend suitable prevention and defence measures to them. **Does the ISG reporting obligation replace sector-specific reporting obligations?** No. Depending on the sector, additional reporting or information obligations may exist, for example for electricity supply operators under the ICT Minimum Standard per the StromVV. The ISG reporting obligation applies in addition. ### Obligations - Ensure that cyberattacks on one's own IT resources can be reported to BACS (Art. 74a(1) ISG). - Report reportable cyberattacks within 24 hours of their discovery; if not all details are yet known, the report must be supplemented as soon as new information becomes available (Art. 74e(1) and (3) ISG). - Include in the report details on the reporting body, the type and execution of the cyberattack, its effects, measures taken and, to the extent known, further planned action (Art. 74e(2) ISG). - Submit the report via the secure electronic transmission system provided by BACS (Art. 74f(1) ISG). Deadlines: - 2025-04-01: The reporting obligation for cyberattacks on critical infrastructure (Art. 74a-74f ISG) enters into force (AS 2024 257; AS 2025 173; BBl 2023 84). Penalties: The reporting obligation provisions themselves (Art. 74a-74f ISG) contain no penalty provision of their own. Per BACS (FAQ on the reporting obligation), BACS can issue a ruling with a threat of penalty if non-reporting is established; in the case of continued non-compliance, a complaint to the competent cantonal prosecution authorities is possible, which are responsible for prosecuting and adjudicating violations of BACS rulings. A quantified fine amount, and a date from which fines can specifically be imposed, could not be evidenced in this research either in the ISG full text or on the BACS pages reached (see unsicher). ### Evidence - Confirmation of report or log from BACS's electronic reporting system. - Internal documentation of incident detection and escalation, showing the relevant discovery time for the 24-hour deadline (Art. 74e ISG). Related to other norms in this knowledge base: nis2, ikt_minimalstandard_stromvv. Not evidenced / open: - The statement given in the brief, 'fines have been possible since 1 October 2025', could not be evidenced either in the ISG full text (Art. 74a-74f contain no penalty provision of their own) or on the BACS pages reached (reporting obligation homepage, FAQ), and is therefore not adopted as fact. - The Cybersecurity Ordinance (CSV), which per BACS regulates details of the reporting obligation and exemptions under Art. 74c ISG, was not read in full text in this research; the SR number and exact content of the CSV are not confirmed. - The simplified formula of 'nine sectors' of critical infrastructure used on bacs.admin.ch does not match the exhaustive list of 21 letters (a-u) in Art. 74b(1) ISG; for this file, the statutory list was used as authoritative. ### Sources - [Bundesgesetz über die Informationssicherheit (Informationssicherheitsgesetz, ISG), SR 128, Stand am 1. April 2025, insbesondere Art. 74a-74f](https://www.fedlex.admin.ch/eli/cc/2022/232/de) — Bundeskanzlei / Fedlex, retrieved 2026-09-24 (primaer) - [Meldepflicht für Cyberangriffe auf kritische Infrastrukturen](https://www.bacs.admin.ch/de/meldepflicht) — Bundesamt für Cybersicherheit (BACS), retrieved 2026-09-24 (behoerde) - [FAQ zur Meldepflicht](https://www.bacs.admin.ch/de/faq-meldepflicht) — Bundesamt für Cybersicherheit (BACS), retrieved 2026-09-24 (behoerde) --- ## ISO 13485 – Medical devices – Quality management systems – Requirements for regulatory purposes (ISO 13485) *ID: `iso13485` · Type: norm · Scope: CH, EU, DE · Basis of obligation: marktgetrieben · As of: 2026-09-24* ### When does ISO 13485 apply to you? ISO 13485 is the international standard for quality management systems specifically for medical device manufacturers. As a standard, it is not itself legally mandated, but in practice it is a precondition for obtaining CE marking under the EU MDR or authorisation via Swissmedic under the MedDO: without a certified QM system to ISO 13485, notified bodies and supervisory authorities generally refuse conformity assessment. Triggers in detail: - **If you manufacture, import or distribute a medical device** (confidence: wahrscheinlich): You manufacture a medical device - ISO 13485 is the de facto basis of every MDR conformity assessment and every Swissmedic authorisation; without a certified QM system, you generally will not get CE marking or market access. - **If your industry is MedTech** (confidence: wahrscheinlich): As a MedTech company, your quality management system is highly likely to be measured against ISO 13485 by customers, notified bodies and supervisory authorities, even though your own certification needs to be checked case by case. - **If you act as a Manufacturer or Supplier – provided that you manufacture, import or distribute a medical device** (confidence: pruefen): As a manufacturer or supplier for medical devices, your customers and the conformity assessment bodies typically require an ISO 13485-certified QM system, including for supplied components or software. Exceptions: - Certification to ISO 13485 is not legally mandatory in every case; for very simple products in a low risk class, a reduced conformity assessment procedure without full ISO 13485 certification may suffice, depending on the jurisdiction. Which product classes this concerns case by case was not verified in this session. - Pure suppliers of non-medical-device components with no specific medical intended purpose do not fall directly within the standard's scope, even though customers can impose contractually similar requirements. ### Why **Is ISO 13485 legally required?** Not the standard itself, directly. Neither the EU MDR nor the Swiss MedDO literally prescribes 'ISO 13485' in their statutory text. In practice, however, it is the accepted evidence basis by which manufacturers meet the QM requirements of the MDR/MedDO - without it, you will in practice not get a conformity assessment. **Isn't ISO 9001 sufficient too?** No. ISO 9001 is a general QM system; ISO 13485 builds on a similar structure but adds additional, medical-device-specific requirements, for example on risk management, traceability and regulatory documentation. Since the 2016 revision, the two standards have diverged more in substance. **Does an ISO 13485 certification automatically apply equally to Switzerland and the EU?** The standard itself is international and region-independent. Whether a specific certification is recognised by the respective notified body or by Swissmedic depends on the accreditation of the certification body in the relevant jurisdiction - this was not examined in detail in this session. ### Obligations - Establish, document, implement and maintain a quality management system per the standard's requirements, across the entire product life cycle from development through manufacturing to post-market surveillance. - Integrate risk management into the QM system (in practice usually in conjunction with ISO 14971). - Ensure traceability of products and processes. - Conduct regular internal audits and management reviews. - Where certified: pass external surveillance audits by an accredited certification body. Penalties: ISO 13485 is not a statutory standard and carries no fines of its own. The de facto compulsion arises via the market: without a valid certificate, notified bodies and Swissmedic generally refuse conformity assessment or authorisation, which amounts to exclusion from the market. Where deviations are found in audit, consequences range from conditions up to withdrawal of the certificate by the certification body. ### Evidence - ISO 13485 certificate from an accredited certification body. - QM manual and documented procedures. - Audit reports (internal and external). - Evidence of risk management, design and development documentation, supplier evaluation. Related to other norms in this knowledge base: mdr, mepv, iec62304, iso9001. Not evidenced / open: - iso.org blocks automated access (HTTP 403 on all attempted URLs, including via curl with a browser user agent); the full text of the standard or the catalogue page could not be read in this session. The current edition stated rests on established professional knowledge (ISO 13485:2016 is the most recently published international edition) and the secondary Johner Institut source, not on a primary text read in this session. - The Johner Institut page summarised via WebFetch inconsistently used the label 'ISO 13485:2021'; this presumably confuses it with the European implementation EN ISO 13485:2016/A11:2021 (an amendment for MDR/IVDR harmonisation), not a new ISO edition of its own. This was not conclusively verified against an iso.org source. - Whether and which product categories can do without full ISO 13485 certification (reduced conformity assessment) was not verified. ### Sources - [ISO 13485:2016 – Medical devices – Quality management systems – Requirements for regulatory purposes](https://www.iso.org/standard/59752.html) — International Organization for Standardization (ISO), retrieved 2026-09-24 (sekundaer) - [ISO 13485 – Alles Wichtige zur Norm für Medizinprodukte-QM-Systeme](https://www.johner-institut.de/blog/regulatory-affairs/iso-13485/) — Johner Institut, retrieved 2026-09-24 (sekundaer) --- ## ISO/IEC 27001 (ISO 27001) *ID: `iso27001` · Type: norm · Scope: CH, EU, DE · Basis of obligation: marktgetrieben · As of: 2026-09-24* ### When does ISO 27001 apply to you? ISO/IEC 27001 is the internationally recognised standard for an information security management system (ISMS); it is voluntary, but is frequently required by large customers, in tenders and in due-diligence reviews. The current version, ISO/IEC 27001:2022, requires a risk-based management system under chapters 4 to 10 and a justified selection from 93 controls in Annex A. A certificate from an accredited certification body is valid for three years and is confirmed through annual surveillance audits. Triggers in detail: - **If you act as a Supplier** (confidence: wahrscheinlich): Large customers and corporate groups increasingly require their suppliers to demonstrate a certified ISMS before entering into a contractual relationship. - **If you supply public-sector clients** (confidence: pruefen): Public-sector tenders in many cases require an ISO 27001 certificate or an equivalent ISMS as an eligibility criterion. - **If your industry is Aviation** (confidence: wahrscheinlich): The European Part-IS regulations expressly allow aviation organisations an information security management system based on ISO/IEC 27001; anyone choosing this route needs the standard as a foundation. - **If you process special category personal data or provide AI systems** (confidence: pruefen): Anyone processing special category data or providing AI systems is frequently asked by customers and investors about a documented information security management system. - **If you are active in the EU or Germany** (confidence: pruefen): In the EU area, an ISO 27001 certificate is a common standard piece of evidence in due-diligence reviews for funding rounds and company sales. Exceptions: - No statutory obligation to be certified; an ISMS can also be operated in line with the standard's principles without external certification. - Micro-enterprises without a contractual requirement from a customer generally have no trigger. ### Why **Does a start-up need to be certified to ISO 27001?** Not legally. But corporate customers, tenders and investors often ask about it. It makes sense to build your processes early on so that a later certification is a small step, not a rebuild. **What does an ISO 27001 certificate show, and what doesn't it show?** It shows that a company operates a functioning, audited information security management system and has made a justified selection of the measures in Annex A. It does not guarantee one hundred percent protection against incidents, but it evidences a structured, repeatedly reviewed approach to risk. **How long is an ISO 27001 certificate valid?** Three years, with annual surveillance audits by the certification body; recertification is then required. **What changes with the 2022 version compared with 2013?** Annex A was reorganised: instead of 114 controls in 14 categories, there are now 93 controls in four themes (organisational, people, physical, technological). ### Obligations - Build an ISMS meeting the requirements of chapters 4 to 10 (context of the organisation, leadership, planning, support, operation, performance evaluation, improvement) - Carry out risk assessment and treatment, including a justified selection of which of the 93 controls in Annex A are applied or excluded (Statement of Applicability) - Conduct internal audits and management review at defined intervals - Continually improve the ISMS Penalties: No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders, loss of large customers, or deductions in due-diligence valuations for investments or company sales are a risk. ### Evidence - Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review) - Annual surveillance audits - Recertification every three years - Statement of Applicability as an internal evidence document Related to other norms in this knowledge base: nis2, cra, tisax, iec62443, easa_partis, dora, finma_rundschreiben. Not evidenced / open: - iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the iso.org URL is kept only as a source reference (source type accordingly 'secondary', since no standard text was read). The facts on Annex A (93 controls, four themes: 37 organisational, 8 people, 14 physical, 34 technological) and on the certification process come from secondary sources (GRC Solutions, ANSI blog search result), not from the ISO original text. - That Part-IS expressly allows an ISMS 'based on ISO/IEC 27001' is evidenced via the FOCA (BAZL) page, but only as a secondary summary (search result), not as a verbatim reading of the regulation's text. - Specific thresholds (e.g. number of employees) from which customers require a certificate were not researched and are deliberately not listed as a trigger. ### Sources - [ISO/IEC 27001:2022 — Information security management systems](https://www.iso.org/standard/27001) — ISO, retrieved 2026-09-24 (sekundaer) - [ISO/IEC 27001:2022 – Information Security Systems](https://blog.ansi.org/anab/iso-iec-27001-2022-information-security-systems/) — ANSI National Accreditation Board (Suchergebnis), retrieved 2026-09-24 (sekundaer) - [ISO/IEC 27001:2022 – The Information Security Management Standard](https://grcsolutions.io/guide-to-iso-iec-27001-2022/) — GRC Solutions, retrieved 2026-09-24 (sekundaer) - [BAZL: EU-Verordnungen zur Informationssicherheit (Part-IS)](https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is) — Bundesamt für Zivilluftfahrt (BAZL), retrieved 2026-09-24 (behoerde) --- ## ISO 9001 (ISO 9001) *ID: `iso9001` · Type: norm · Scope: CH, EU, DE · Basis of obligation: marktgetrieben · As of: 2026-09-24* ### When does ISO 9001 apply to you? ISO 9001 is the internationally recognised standard for quality management systems, voluntary, but often contractually required in manufacturing and supply chains as well as in public tenders. It is built on the PDCA cycle (Plan-Do-Check-Act) and is audited by accredited certification bodies, with a validity of three years and annual surveillance audits. ISO published the new ISO 9001:2026 version on 16 September 2026; existing certificates to ISO 9001:2015 remain valid until 30 September 2029 at the latest. Triggers in detail: - **If your industry is Manufacturing** (confidence: wahrscheinlich): In manufacturing and supply chains, a certified quality management system is a common precondition for even being listed as a supplier. - **If your industry is MedTech** (confidence: wahrscheinlich): In medical technology, ISO 9001 is the basis that the sector-specific ISO 13485 builds on; without a functioning quality management system, 13485 certification is not achievable. - **If you supply public-sector clients** (confidence: pruefen): Public tenders in manufacturing and services frequently require a certified quality management system as an eligibility criterion. - **If you act as a Supplier** (confidence: wahrscheinlich): Large customers in supply chains regularly check suppliers for a certified quality management system before awarding contracts. - **If you supply the automotive industry** (confidence: pruefen): Automotive manufacturers and their suppliers require a quality management system to ISO 9001 as the basis on which sector-specific requirements such as IATF 16949 build. Exceptions: - No legal obligation to be certified. - For micro-enterprises without a specific customer requirement, there is generally no trigger. - Medical technology companies generally need the sector-specific ISO 13485 in addition to ISO 9001; this is only mentioned here, with detail covered in a separate file (iso13485). ### Why **Is ISO 9001 legally required?** No. The standard is voluntary, but is often contractually required in manufacturing and supply chains as well as in public tenders. **What changes with ISO 9001:2026?** ISO published the new version on 16 September 2026; it replaces ISO 9001:2015 and, per certification bodies, brings among other things stronger requirements on resilience, supply chain management, sustainability, leadership responsibility, and managing risks and opportunities. Existing certificates to the old version remain valid until 30 September 2029 at the latest. **Is ISO 9001 sufficient for medical technology?** Generally not on its own. Medical technology companies also need the sector-specific ISO 13485, which builds on the same principles but imposes additional regulatory requirements. ### Obligations - Establish a quality management system following the PDCA cycle (Plan-Do-Check-Act) - Documented processes, responsibilities and evidence (control of documents and records) - Internal audits and management review - Measures for continual improvement and for managing risks and opportunities Deadlines: - 2026-09-16: Publication of ISO 9001:2026 by ISO (supersedes ISO 9001:2015) - 2029-09-30: Existing certificates to ISO 9001:2015 lose validity at the latest on this date (three-year transition period) Penalties: No fine, since voluntary; in practice: without a valid certificate, exclusion from tenders and supplier lists is a risk, particularly in manufacturing and supply chains. ### Evidence - Certificate from an accredited certification body following a Stage 1 audit (document review) and Stage 2 audit (implementation review) - Annual surveillance audits - Recertification every three years - For existing ISO 9001:2015 certificates: validity ends 30 September 2029 at the latest, after which certification to ISO 9001:2026 is required Related to other norms in this knowledge base: iso27001, iso13485, mdr, mepv, cra. Not evidenced / open: - iso.org responded to direct retrieval in this session with HTTP 403 (bot block); the facts on the 2026 revision come from the secondary sources TÜV and DNV, which agree on the publication date (16.09.2026) and the transition period (until 30.09.2029), but were not checked against the ISO original text. - The exact substantive scope of the changes from 2015 to 2026 (resilience, supply chain management, sustainability, leadership responsibility) is evidenced only via a secondary source (TÜV), not checked against the ISO original text. - Whether and how the PDCA cycle remains explicitly named in the 2026 version was not examined in this session. - An earlier note in the architecture document ('ISO 9001 revision not checked') is resolved by this research step: the revision is published (16.09.2026), evidenced via two consistent secondary sources, not via the ISO original text. ### Sources - [ISO 9001:2015 — Quality management systems — Requirements](https://www.iso.org/standard/62085.html) — ISO, retrieved 2026-09-24 (sekundaer) - [ISO 9001:2026 — Quality management systems — Requirements](https://www.iso.org/standard/9001) — ISO, retrieved 2026-09-24 (sekundaer) - [Overview & schedule: Revision of ISO 9001 coming in 2026](https://www.tuv.com/world/en/revision-iso-9001-2026.html) — TÜV (TÜV Rheinland-Gruppe), retrieved 2026-09-24 (sekundaer) - [ISO 9001:2026 Revision: Changes & Transition](https://www.dnv.us/assurance/Management-Systems/new-iso/transition/iso-9001-revision/) — DNV, retrieved 2026-09-24 (sekundaer) --- ## Machinery Regulation (EU Machinery Regulation) (Machinery Regulation (EU) 2023/1230) *ID: `maschinenverordnung_2023_1230` · Type: verordnung · Scope: EU · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does Machinery Regulation (EU) 2023/1230 apply to you? The EU Machinery Regulation (Regulation (EU) 2023/1230) supersedes the previous Machinery Directive 2006/42/EC and applies from 20 January 2027 to the placing on the market of machinery in the EU. New are explicit cybersecurity requirements: machinery with digital elements or safety-relevant functions must be designed so that its safety functions cannot be compromised by unauthorised digital interference. For Swiss machinery manufacturers, the regulation applies as soon as they place their products on the EU market. Triggers in detail: - **If you manufacture products with embedded software** (confidence: wahrscheinlich): Your machinery contains digital elements or software-controlled safety functions - from January 2027, the EU Machinery Regulation additionally requires, on top of the existing safety requirements, protection against unauthorised digital interference (Annex III, including sections 1.1.9 and 1.2.1). - **If you act as a Manufacturer – provided that you manufacture products with embedded software** (confidence: wahrscheinlich): As the manufacturer of machinery with digital elements, you bear the main responsibility for conformity assessment under the Machinery Regulation; importers and distributors who make safety-relevant changes to the machinery are also treated as manufacturers with corresponding obligations. This file specifically covers the new cybersecurity requirements; for machinery with no digital elements at all, check the regulation's classic safety requirements separately. - **If you are active in the EU – provided that you manufacture products with embedded software** (confidence: pruefen): The Machinery Regulation is triggered by placing on the EU market - if you place machinery with digital elements on the market in the EU, the cybersecurity requirements described here apply regardless of your registered seat in Switzerland. - **If your industry is Manufacturing** (confidence: pruefen): In manufacturing and mechanical engineering, safety functions are increasingly digitally controlled - check whether your machinery falls under the regulation's new cybersecurity requirements. ### Why **From when does the new Machinery Regulation apply as binding?** From 20 January 2027, only machinery that complies with Regulation (EU) 2023/1230 may be placed on the market in the EU; it supersedes the previous Machinery Directive 2006/42/EC. **What is new about the cybersecurity requirements compared with the old Machinery Directive?** For the first time, software safety, protection against unauthorised digital interference, and risks from AI algorithms become an explicit part of the essential safety requirements and conformity assessment (Annex III, including sections 1.1.9 and 1.2.1) - the old directive had no such specific cybersecurity requirements. **How does the Machinery Regulation relate to the Cyber Resilience Act?** Both frameworks address cybersecurity for connected products, but the Machinery Regulation is the more specific regime for machinery and its safety functions. The details of how the two frameworks are demarcated case by case have not been conclusively clarified in this knowledge base; see the separate norm file cra. ### Obligations - Ensure that machinery is protected against unintentional or deliberate corruption of its safety-relevant software or data (Annex III section 1.1.9). - Ensure the safety and reliability of controls, including protection against disrupted wireless connections and malfunctions caused by AI components (Annex III section 1.2.1). - Provide for evidence or logging of legitimate and illegitimate interference with safety-relevant components. - Carry out CE marking and conformity assessment under the Machinery Regulation; per secondary sources, a combined conformity assessment with the EU AI Act is envisaged where AI safety functions are integrated. - Maintain technical documentation including cybersecurity evidence. Deadlines: - 2027-01-20: Regulation (EU) 2023/1230 applies to the placing on the market of machinery and supersedes the Machinery Directive 2006/42/EC. Penalties: The Machinery Regulation itself primarily harmonises safety requirements and conformity assessment; sanctions for breaches (e.g. market surveillance measures, fines) are governed by the national law of the member states and were not researched in this session. ### Evidence - Technical documentation with cybersecurity evidence (Annex III section 1.1.9). - Declaration of conformity and CE marking. - Logs of interference with safety-relevant components. Related to other norms in this knowledge base: cra, mdr. Not evidenced / open: - The EUR-Lex primary text of Regulation (EU) 2023/1230 (eur-lex.europa.eu/eli/reg/2023/1230/oj) was not retrievable in this session (HTTP 503 or empty response); all statements come from two independent secondary sources (professional articles), not from the regulation's text itself. - The date of entry into force or publication of the regulation was not verified and is therefore not listed - only the application date of 20.1.2027 is evidenced. - Specific exemptions from the scope (e.g. for certain machinery categories, as under the old Machinery Directive) were not named in the sources retrieved and are therefore not documented; the 'ausnahmen' field is accordingly empty rather than guessed. - Sanctions/fine ranges for breaches were not researched (governed by the national law of the member states). - The statement on a combined conformity assessment with the EU AI Act for integrated AI safety functions comes from a single secondary source and was not cross-checked. ### Sources - [EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027](https://de.nttdata.com/insights/blog/eu-maschinenverordnung-2023-1230-neue-cybersecurity-anforderungen-fuer-hersteller-ab-2027) — NTT DATA Deutschland, retrieved 2026-09-24 (sekundaer) - [Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit](https://www.weka.de/produktsicherheit/maschinenverordnung-eu-2023-1230-anforderungen-an-digitale-technologien-und-cybersicherheit/) — WEKA Business Medien, retrieved 2026-09-24 (sekundaer) --- ## Regulation (EU) 2017/745 on medical devices (EU MDR) *ID: `mdr` · Type: verordnung · Scope: EU · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does EU MDR apply to you? The EU Medical Device Regulation (MDR, Regulation (EU) 2017/745) governs conformity assessment, CE marking, technical documentation and market surveillance for medical devices in the EU; it has applied since 26 May 2021. Since that date, Switzerland has been a third country for the EU, because the mutual recognition agreement (MRA) was not updated - Swiss manufacturers therefore need an authorised representative in the EU for the EU market. Software can itself be a medical device, and the MDR sets its own requirements on IT security for it in Annex I. Triggers in detail: - **If you manufacture, import or distribute a medical device** (confidence: sicher): You manufacture, import or distribute a medical device - the MDR sets out how you must assess conformity, document and CE-mark it as soon as the product enters the market in the EU. - **If your industry is MedTech** (confidence: wahrscheinlich): As a MedTech company, you are highly likely to develop or distribute products that fall under the MDR's definition of a 'medical device' - check the classification based on your specific intended purpose. - **If you are active in the EU or Germany – provided that you manufacture, import or distribute a medical device** (confidence: pruefen): You are active on the EU market (or in Germany) and manufacture or distribute medical devices - even as a Swiss company, this makes you subject to the MDR. As a Swiss manufacturer, you additionally need an authorised representative in the EU since 26.5.2021. - **If you act as a Manufacturer – provided that you manufacture, import or distribute a medical device** (confidence: pruefen): As the manufacturer of a medical device, you bear the main responsibility under the MDR for conformity assessment, technical documentation, post-market surveillance and - if you are based in Switzerland and supply the EU - appointing an EU authorised representative. For manufacturers of other products, the MDR does not apply. Exceptions: - Custom-made devices (products individually made for a specific patient) are subject to adapted, reduced requirements instead of the full conformity assessment. - Pure in-vitro diagnostics do not fall under the MDR but under the separate IVDR (Regulation (EU) 2017/746). - For in-house manufacture and use of products within a health institution without supply to third parties, relief from certain MDR obligations applies under narrow conditions. - The exact article and paragraph numbers of these exemptions were not verified in this session via full-text retrieval from EUR-Lex (see 'unsicher'). ### Why **We are a Swiss manufacturer and sell only in Switzerland - does the MDR affect us?** Not directly, as long as you operate exclusively on the Swiss market; there, the MedDO applies. As soon as you place a product on the market in the EU, the MDR applies and you need an authorised representative in the EU. **Is our software automatically a medical device?** No, that depends on the intended purpose. Software used for medical purposes such as diagnosis, monitoring or treatment support can itself qualify as a medical device and must then meet the MDR's requirements, even if it is not a hardware component. **What does Switzerland's third-country status specifically mean for us as a manufacturer?** Since 26.5.2021 you need an authorised representative established in the EU to represent your products there, and you no longer have direct access to the EU database EUDAMED or to the information exchange of European authorities. At the same time, EU manufacturers supplying Switzerland must appoint a Swiss authorised representative. ### Obligations - Carry out a conformity assessment procedure matching the product's risk class (Class I to III), including involving a notified body for higher classes. - Draw up and keep current technical documentation evidencing the product's design, manufacture and safety. - For software that is itself a medical device or embedded in one: meet the Annex I requirements on the design and manufacture of electronic programmable systems, including IT security measures and protection against unauthorised access, aligned with the state of the art. - Apply CE marking only after successful conformity assessment. - Operate post-market surveillance and a vigilance system (reporting of serious incidents). - As a Swiss manufacturer: appoint an authorised representative established in the EU before the product is placed on the market there. - Register the manufacturer, authorised representative and product in the EU database EUDAMED, to the extent the respective modules are already mandatory. Deadlines: - 2021-05-26: The MDR (Regulation (EU) 2017/745) becomes applicable; from this date, Switzerland is treated as a third country by the EU in medical device law, because the MRA was not updated. Penalties: The MDR itself does not prescribe uniform fines; EU member states set effective, proportionate and dissuasive sanctions for breaches in their national law. Market surveillance authorities can additionally order sales bans, recalls and withdrawal of CE marking. The exact enabling provision in the MDR was not verified via full-text retrieval in this session (see 'unsicher'). ### Evidence - Technical documentation under Annex II/III of the MDR. - EU declaration of conformity. - CE marking with the notified body's identification number (where required). - Certificate from the notified body (for Class IIa, IIb, III and certain Class I products). - Evidence of an appointed EU authorised representative where based outside the EU, including the mandate document under Annex II of the MDR. Related to other norms in this knowledge base: mepv, iso13485, iec62304, cra, dsgvo, revdsg, eu_ai_act. Not evidenced / open: - The exact wording of Annex I section 17 of the MDR (subsections on IT security) could not be verified via full-text retrieval from EUR-Lex in this session - EUR-Lex blocked automated access (WebFetch and curl repeatedly returned empty responses with HTTP 202/404). The description rests on the website's existing content and established professional knowledge, not on a primary text read in this session. - The exact article number of the MDR's enabling provision for sanctions (presumably Art. 113) was not verified via full text. - The exact article/paragraph numbers of the exemptions named (custom-made devices, IVDR demarcation, in-house manufacture) were not verified via full-text retrieval. - The exact title and content of the 'Notice to Stakeholders' on the Switzerland-EU MRA status, mentioned by the European Commission, could not be retrieved directly (404 at the presumed URL); its existence is evidenced via the health.ec.europa.eu page, not its wording. ### Sources - [Verordnung (EU) 2017/745 des Europäischen Parlaments und des Rates über Medizinprodukte (MDR)](https://eur-lex.europa.eu/eli/reg/2017/745/oj) — Europäisches Parlament und Rat der Europäischen Union / EUR-Lex, retrieved 2026-09-24 (sekundaer) - [Neue Regulierung der Medizinprodukte ab 26. Mai 2021](https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html) — Swissmedic, retrieved 2026-09-24 (behoerde) - [Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)](https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf) — Swissmedic, retrieved 2026-09-24 (behoerde) - [Medical devices – new regulations](https://health.ec.europa.eu/medical-devices-sector/new-regulations_en) — Europäische Kommission, Generaldirektion Gesundheit und Lebensmittelsicherheit (DG SANTE), retrieved 2026-09-24 (behoerde) --- ## Medical Devices Ordinance of 1 July 2020 (SR 812.213) (MedDO) *ID: `mepv` · Type: verordnung · Scope: CH · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does MedDO apply to you? The Swiss Medical Devices Ordinance (MedDO, SR 812.213) governs the manufacture, placing on the market and surveillance of medical devices in Switzerland and is supervised by Swissmedic. It was brought into force in a completely revised version on 26 May 2021 and closely follows the substance of the EU MDR (Regulation (EU) 2017/745), but remains independent Swiss law with its own authorisation, registration and supervisory logic via Swissmedic instead of EU authorities. Triggers in detail: - **If you manufacture, import or distribute a medical device** (confidence: sicher): You manufacture, import or distribute a medical device in Switzerland - the MedDO sets out which conformity evidence, registrations and notifications you must provide to Swissmedic. - **If you are active in Switzerland – provided that you manufacture, import or distribute a medical device** (confidence: pruefen): You are active on the Swiss market and manufacture, import or distribute medical devices - for this, the MedDO applies to you under Swissmedic's supervision, regardless of whether you are also active in the EU. - **If your industry is MedTech** (confidence: wahrscheinlich): As a MedTech company with Swiss market relevance, you are highly likely to fall under the MedDO - check the classification of your product based on its intended purpose. - **If you act as a Manufacturer or Distributor – provided that you manufacture, import or distribute a medical device** (confidence: pruefen): As a manufacturer or distributor of medical devices in Switzerland, you have your own obligations under the MedDO, including registration with Swissmedic (Swiss Single Registration Number, CHRN) and appointing a Swiss authorised representative if you are based abroad. Exceptions: - Custom-made devices and manufacturing-specific regulated exemptions carry, analogous to the MDR, adapted rather than full conformity requirements. - For products already lawfully placed on the market under the old law before the revised MedDO applied, transition periods existed; whether and for which product categories these are still relevant in September 2026 was not verified in this session. - The exact article and paragraph numbers of these exemptions were not verified via full-text retrieval from Fedlex (see 'unsicher'). ### Why **Is CE marking under the EU MDR sufficient to sell in Switzerland?** Not automatically as a full substitute for the Swiss obligations: you additionally need a Swiss authorised representative (if based abroad) and registration with Swissmedic. In substance, the MedDO closely follows the MDR, but it is independent Swiss law with its own registration logic. **Who supervises compliance with the MedDO?** Swissmedic, the Swiss Agency for Therapeutic Products. It carries out market surveillance, receives vigilance reports, and issues the Swiss Single Registration Number (CHRN). **What does 'substantively aligned with the MDR' specifically mean?** Switzerland has largely adopted the substantive requirements of the EU MDR into its own law, to maintain equivalence and make later EU market access easier for Swiss manufacturers. Legally, however, it is an independent Swiss ordinance with its own supervision, not a direct application of the EU MDR. ### Obligations - Carry out conformity assessment and classify the product by risk class, substantively aligned with the MDR system. - Draw up technical documentation and make it available to Swissmedic on request. - As manufacturer, authorised representative or importer: register with Swissmedic and obtain a Swiss Single Registration Number (CHRN). - As a foreign manufacturer with no seat in Switzerland: appoint an authorised representative established in Switzerland who carries out the regulatory obligations towards Swissmedic (mirroring the obligation of Swiss manufacturers to appoint an EU authorised representative). - Operate a vigilance system and report serious incidents to Swissmedic. - Ensure post-market surveillance and keep the product file current. Deadlines: - 2021-05-26: Entry into force of the completely revised MedDO (enactment date of the ordinance: 1 July 2020) and of the new ordinance on clinical trials with medical devices; simultaneously the start of Switzerland's third-country status towards the EU in medical device law. Penalties: Breaches of the MedDO are penalised via the penal provisions of the Therapeutic Products Act (TPA); depending on severity and intent, the range extends to imprisonment or fines. In addition, Swissmedic as the supervisory authority can order sales bans, recalls and withdrawal of registrations or licences. The exact article numbers of the TPA were not verified via full text in this session (see 'unsicher'). ### Evidence - Technical documentation per the requirements set out in the MedDO, aligned with the MDR. - Manufacturer's declaration of conformity. - Swiss Single Registration Number (CHRN) for manufacturers, authorised representatives and importers. - Certificate from a conformity assessment body, where required for the risk class. - Evidence of an appointed Swiss authorised representative where the manufacturer's seat is outside Switzerland. Related to other norms in this knowledge base: mdr, iso13485, iec62304, dsgvo, revdsg. Not evidenced / open: - The full text of the MedDO on Fedlex (SR 812.213) could not be read in an automated way in this session: Fedlex serves bots only the JavaScript application shell (WebFetch and several curl variants, including guessed filestore paths, returned identical empty shell pages). The substantive statements rest on the Swissmedic notice of 26.5.2021 (authority source, read in full text) and the Swissmedic factsheet on the obligations of economic operators, not on the ordinance's text itself. - The exact article numbers on transition periods for legacy products, and on the penal provisions in the TPA, were not verified via full text. - Whether and which transition periods from the 2020/2021 revision are still actively relevant in September 2026 was not examined. ### Sources - [Medizinprodukteverordnung vom 1. Juli 2020 (MepV, SR 812.213)](https://www.fedlex.admin.ch/eli/cc/2020/552/de) — Schweizerischer Bundesrat / Fedlex (Systematische Rechtssammlung des Bundes), retrieved 2026-09-24 (sekundaer) - [AS 2021 281 – Änderung der Medizinprodukteverordnung](https://www.fedlex.admin.ch/eli/oc/2021/281/de) — Fedlex, Amtliche Sammlung des Bundesrechts, retrieved 2026-09-24 (sekundaer) - [Neue Regulierung der Medizinprodukte ab 26. Mai 2021](https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html) — Swissmedic, retrieved 2026-09-24 (behoerde) - [Merkblatt: Pflichten der Wirtschaftsakteure in der Schweiz (MU600_00_016d)](https://www.swissmedic.ch/dam/swissmedic/de/dokumente/medizinprodukte/mep_urr/mu600_00_016d_mb_pflichten_wirtschaftsakteure_ch.pdf.download.pdf/MU600_00_016d_MB_Pflichten_Wirtschaftsakteure_CH.pdf) — Swissmedic, retrieved 2026-09-24 (behoerde) --- ## Directive on measures for a high common level of cybersecurity across the Union (NIS2) (NIS2) *ID: `nis2` · Type: gesetz · Scope: EU, DE · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does NIS2 apply to you? The NIS2 Directive (Directive (EU) 2022/2555) obliges operators in critical and important sectors to manage risk and report significant security incidents. As an EU directive, it does not have direct effect but works via national transposition laws - in Germany via the NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025. NIS2 affects Swiss companies via an EU establishment, via the representative obligation for certain digital services under Art. 26, or because EU customers must demonstrate their supply chain security and pass this requirement on. Triggers in detail: - **If you operate critical infrastructure** (confidence: wahrscheinlich): You state that you operate critical infrastructure - the NIS2 sector lists in Annex I (including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space) and Annex II (including postal/courier services, waste management, chemicals, food, manufacturing, digital services, research) are a strong indication that NIS2 is relevant to you. - **If your industry is Energy** (confidence: wahrscheinlich): Energy supply is one of the eleven sectors of high criticality in Annex I of the NIS2 Directive - as an operator in this sector, NIS2 checks whether you reach the size threshold for 'important' or 'essential' entities. - **If your industry is Software/SaaS** (confidence: pruefen): Digital infrastructure and certain digital services (cloud, data centres, managed services, online marketplaces, search engines, social networks) fall under Annex I or II of the NIS2 Directive - whether your specific offering is covered depends on the exact type of service. - **If you have 50 or more employees – provided that your industry is Energy or Software/SaaS** (confidence: pruefen): From around 50 employees and the associated revenue or balance-sheet thresholds, companies in the NIS2 sectors generally count as an 'important entity' - what additionally matters is whether your activity is assigned to a sector under Annex I or II at all. Outside these sectors, the number of employees alone does not trigger NIS2. - **If you are active in the EU** (confidence: pruefen): If, as a provider of certain digital services (e.g. DNS, cloud, data centre, content delivery, managed service or managed security service, online marketplace, search engine, social network), you offer your services in the EU without being established there, you must appoint a representative in an EU member state under Art. 26(3) NIS2. Exceptions: - Micro and small enterprises (below the thresholds for medium-sized enterprises under Recommendation 2003/361/EC) generally do not fall under NIS2 - unless they belong to the exemptions from the size rule named in Art. 2(2) NIS2 (including providers of public electronic communications networks/services, trust service providers, TLD name registries and DNS service providers, sole providers of a service important to society in a member state, certain public administration bodies, entities identified as critical under the CER Directive (EU) 2022/2557). - Member states can additionally extend the scope to local administrative units and certain educational institutions with critical research activity. ### Why **Does a Swiss company without an EU establishment have to implement NIS2 directly?** Only directly if it offers one of the digital services named in Art. 26(1)(b) (e.g. DNS, cloud, data centre, content delivery network, managed service/managed security service, online marketplace, search engine, social network) in the EU and must appoint a representative for that. Otherwise, NIS2 usually affects Swiss companies indirectly - via an EU establishment or via supply chain requirements from EU customers. **What is the difference between 'essential' and 'important' entities?** The classification depends on sector and size: in particularly critical sectors (Annex I), large companies generally count as an 'essential entity', medium-sized companies in Annex I or Annex II sectors generally as an 'important entity'. The same risk management and reporting obligations apply to both categories, but with different supervisory intensity and fine ranges. **Does NIS2 apply uniformly across the EU?** No. NIS2 is a directive and must be transposed into national law by each member state; details on sector demarcation, reporting deadlines and supervision can vary nationally. This file primarily covers the German transposition (NIS2UmsuCG). ### Obligations - Implement state-of-the-art cybersecurity risk management measures, at minimum: risk analysis/security policy, incident handling, business continuity/backup/disaster recovery/crisis management, supply chain security, security in system acquisition/development/maintenance including vulnerability management, assessment of the effectiveness of measures, cyber hygiene and training, cryptography/encryption policy, personnel security/access control/asset management, multi-factor authentication (Art. 21(2) NIS2). - Take into account security in the supply chain, including relationships with direct suppliers and service providers (Art. 21(3) NIS2). - Report significant security incidents to the competent authority: early warning within 24 hours, notification within 72 hours, final report within one month (in Germany, to the BSI). - In Germany: register as a NIS2 company via 'Mein Unternehmenskonto' and the BSI portal. - Where Art. 26(3) applies: appoint in writing a representative in a member state where the services are offered. Deadlines: - 2024-10-17: Deadline for transposing the NIS2 Directive into national law (Art. 41 NIS2) - missed by several member states, including Germany. - 2025-12-06: The German NIS2 Implementation Act (NIS2UmsuCG) enters into force. - 2026-01-06: The BSI portal for NIS2 registration goes live. Penalties: Under Art. 34 NIS2, the fine ranges for 'essential entities' must be at least EUR 10 million or 2% of worldwide annual turnover (whichever is higher), and for 'important entities' at least EUR 7 million or 1.4% of worldwide annual turnover. The specific implementation and fine amount is governed by national law, in Germany by the NIS2 Implementation Act. ### Evidence - Documented risk management framework under Art. 21(2). - Evidence of registration (in Germany: the BSI portal). - Reporting logs for security incidents. - Supply chain assessment of security-relevant suppliers and service providers. - Evidence of the representative appointment under Art. 26(3), where applicable. Related to other norms in this knowledge base: isg_meldepflicht, ikt_minimalstandard_stromvv. Not evidenced / open: - The EUR-Lex primary text of Directive (EU) 2022/2555 was not retrievable in this session (empty/blocked response across several URL forms); article texts were verified via the secondary source nis-2-directive.com and sector lists via buzer.de, not via the Official Journal itself. - The exact revenue/balance-sheet thresholds for 'essential' (per secondary sources approx. ≥250 employees or >EUR 50 million turnover or >EUR 43 million balance sheet total) and 'important' entities (approx. ≥50 employees or >EUR 10 million turnover/balance sheet total) were not verified directly against Art. 2 NIS2 or the underlying Recommendation 2003/361/EC. - The German reporting deadlines (24h/72h/1 month) are the NIS2 reference values; the exact design in the German NIS2UmsuCG statutory text was not checked in full text. ### Sources - [NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung)](https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html) — Bundesamt für Sicherheit in der Informationstechnik (BSI), retrieved 2026-09-24 (behoerde) - [NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel)](https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html) — nis-2-directive.com, retrieved 2026-09-24 (sekundaer) - [NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel)](https://www.nis-2-directive.com/NIS_2_Directive_Article_26.html) — nis-2-directive.com, retrieved 2026-09-24 (sekundaer) - [NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel)](https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html) — nis-2-directive.com, retrieved 2026-09-24 (sekundaer) - [NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel)](https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html) — nis-2-directive.com, retrieved 2026-09-24 (sekundaer) - [Sektoren mit hoher Kritikalität – Anhang I NIS2](https://www.buzer.de/I_NIS2.htm) — buzer.de, retrieved 2026-09-24 (sekundaer) - [Sonstige kritische Sektoren – Anhang II NIS2](https://www.buzer.de/II_NIS2.htm) — buzer.de, retrieved 2026-09-24 (sekundaer) --- ## Federal Act on Data Protection (Data Protection Act, FADP) (FADP) *ID: `revdsg` · Type: gesetz · Scope: CH · Basis of obligation: gesetzlich · As of: 2026-09-24* ### When does FADP apply to you? The revised Federal Act on Data Protection (FADP, SR 235.1) has, since 1 September 2023, governed the processing of personal data of natural persons by private companies and federal bodies in Switzerland. It obliges controllers, among other things, to data protection by design and by default (Art. 7 FADP), to keep a record of processing activities (Art. 12 FADP, with an exemption for most SMEs), and to notify data security breaches to the Federal Data Protection and Information Commissioner (FDPIC, Art. 24 FADP). Triggers in detail: - **If you process customers' personal data** (confidence: sicher): You process personal data of customers - this makes you subject to the basic obligations of the FADP as soon as the processing has an effect in Switzerland (Art. 2 f. FADP). - **If you process special category personal data** (confidence: sicher): You process special categories of personal data (e.g. health, biometric or religious data) - stricter requirements apply to this under Art. 5(c) and Art. 6(7) FADP, including on consent. - **If you are active in Switzerland – provided that you are active in Switzerland** (confidence: sicher): Your activity is (also) directed at the Swiss market - even simply as an employer, you process personal data of your employees (HR data), even without separate customer data processing. Under Art. 3 FADP, the act applies to every processing that has an effect in Switzerland, regardless of where your company is based. - **If you have 250 or more employees** (confidence: sicher): With 250 or more employees on 1 January of the year, the SME exemption from the record of processing activities under Art. 12(5) FADP and Art. 24 DPO does not apply to you - you must keep such a record. Exceptions: - Purely private, exclusively personal processing of personal data does not fall under the act (Art. 2(2)(a) FADP). - Companies and other private-law organisations, as well as natural persons, employing fewer than 250 employees on 1 January of a year are exempt from the duty to keep a record of processing activities - unless special categories of personal data are processed on a large scale or high-risk profiling is carried out (Art. 12(5) FADP in conjunction with Art. 24 DPO). - The FADP protects only natural persons; the processing of data of legal entities does not fall under it (Art. 1 FADP). - The Federal Assembly, the Federal Council, the federal courts, as well as the Office of the Attorney General and adjudicating federal authorities, are exempt from FDPIC supervision for certain proceedings (Art. 4(2) FADP). ### Why **Does every company have to keep a record of processing activities?** No. Under Art. 24 DPO, companies and other private-law organisations, as well as natural persons, employing fewer than 250 employees on 1 January of a year are exempt from this duty - unless they process special categories of personal data on a large scale or carry out high-risk profiling. Both elements (size and type of processing) must be checked together. **From when does the FADP apply?** Since 1 September 2023. **Who supervises compliance?** The Federal Data Protection and Information Commissioner (FDPIC, Art. 4 FADP), with the exception of the Federal Assembly, the Federal Council, the federal courts, and certain proceedings of the Office of the Attorney General and adjudicating federal authorities. **What must a notification to the FDPIC of a data security breach contain?** Under Art. 15 DPO, at minimum: the type of breach, where possible its time and duration, the categories and approximate number of persons or personal data affected, the consequences including any risks, measures taken or planned, and the contact details of a contact person. Missing details can be submitted later. ### Obligations - Comply with processing principles: lawfulness, good faith, proportionality, purpose limitation (Art. 6 FADP). - Ensure data protection by design and by default, starting already at the planning stage (Art. 7 FADP). - Ensure adequate data security through suitable technical and organisational measures (Art. 8 FADP). - Keep a record of processing activities, unless an SME exemption applies (Art. 12 FADP, Art. 24 DPO). - Inform data subjects appropriately when collecting personal data (Art. 19 FADP). - For processing likely to result in a high risk to personality or fundamental rights, carry out a data protection impact assessment in advance (Art. 22 FADP). - Notify the FDPIC as quickly as possible of data security breaches likely to result in a high risk to the data subject, with the mandatory details under Art. 15 DPO (Art. 24 FADP). - Grant data subjects the right of access, generally within 30 days (Art. 25 FADP, Art. 18 DPO). Deadlines: - 2023-09-01: The revised FADP and the Data Protection Ordinance (DPO) enter into force (Art. 74(2) FADP in conjunction with the Federal Council decision of 31 August 2022). Penalties: Fines of up to CHF 250,000 for private individuals for wilful breach of information, access and cooperation obligations (Art. 60 FADP) or of due-diligence obligations such as unlawful disclosure of personal data abroad, faulty transfer to a processor, or non-compliance with the Federal Council's minimum data security requirements (Art. 61 FADP). Breach of professional confidentiality (Art. 62 FADP) and disregard of FDPIC rulings (Art. 63 FADP) also carry fines of up to CHF 250,000. Administrative criminal law applies to violations within business operations (Art. 64 FADP); prosecution and adjudication fall to the cantons (Art. 65 FADP), and the limitation period for prosecution is five years (Art. 66 FADP). A breach of the notification duty for data security breaches (Art. 24 FADP) is not listed as a separate offence in the penal provisions (Art. 60-64 FADP). ### Evidence - Documented record of processing activities with the minimum details under Art. 12(2) FADP. - Documentation of data protection impact assessments carried out, to be retained for at least two years after completion of the processing (Art. 14 DPO). - Documentation of reported data security breaches with type, effects and measures, to be retained for at least two years from the report (Art. 15(4) DPO). - Evidence of the technical and organisational measures taken for data security (Art. 8 FADP). Related to other norms in this knowledge base: dsgvo. Not evidenced / open: - The Data Protection Ordinance (DPO, SR 235.11) was not read in full text; only Art. 1 and Art. 11-34 (including Art. 15 notification, Art. 24 SME exemption) were read; the remaining approximately 10 articles of the roughly 20 pages were not examined. - The FDPIC's exact investigative and ruling powers (Art. 49-51 FADP) were not checked in full wording; only the context from Art. 52 FADP (procedure) is available. - Note on naming: the name 'VDSG' used in the brief refers to the old 1993 ordinance to the DSG; the current ordinance cited here is correctly called the 'Data Protection Ordinance (DPO)', SR 235.11. ### Sources - [Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023](https://www.fedlex.admin.ch/eli/cc/2022/491/de) — Bundeskanzlei / Fedlex, retrieved 2026-09-24 (primaer) - [Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023](https://www.fedlex.admin.ch/eli/cc/2022/568/de) — Bundeskanzlei / Fedlex, retrieved 2026-09-24 (primaer) - [EDÖB - Aufsichtsbehörde für Datenschutz](https://www.edoeb.admin.ch/edoeb/de/home.html) — Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), retrieved 2026-09-24 (behoerde) --- ## TISAX (Trusted Information Security Assessment Exchange) (TISAX) *ID: `tisax` · Type: branchenstandard · Scope: CH, EU, DE · Basis of obligation: marktgetrieben · As of: 2026-09-24* ### When does TISAX apply to you? TISAX is an information security assessment procedure for the automotive supply chain, run by the ENX Association based on the VDA ISA assessment catalogue. It is not a law and not a public certificate, but a result label shared via the ENX portal and contractually required by vehicle manufacturers and large suppliers. The ENX Association was founded by several European vehicle manufacturers, national automotive associations and suppliers; TISAX is therefore not limited to German manufacturers but is carried by the European industry and performed by audit providers worldwide. Triggers in detail: - **If you supply the automotive industry** (confidence: sicher): Anyone supplying the automotive industry is contractually required by manufacturers and large tier-1 suppliers to hold a valid TISAX result before sensitive design or production data is exchanged. - **If your industry is Manufacturing – provided that you supply the automotive industry** (confidence: wahrscheinlich): In manufacturing, vehicle manufacturers regularly check their supply chain via the ENX portal for a valid TISAX result before awarding contracts - this concerns you if you specifically operate as an automotive supplier. - **If you act as a Supplier – provided that you supply the automotive industry** (confidence: wahrscheinlich): As a supplier in the automotive value chain, a TISAX result frequently becomes a condition for new contracts and for exchanging development data. This does not apply to suppliers outside the automotive industry. - **If you are active in the EU, Germany or many markets worldwide – provided that you supply the automotive industry** (confidence: pruefen): TISAX is not a purely German matter: the assessment procedure is carried by several European vehicle manufacturers and associations and is performed by audit providers worldwide, which is why, as an automotive supplier, it can become a condition outside Germany as well. Exceptions: - Not a law and not a state obligation; the requirement arises exclusively contractually via customers in the automotive supply chain. - Assessment Level 1 (pure self-assessment without external review) does not lead to a TISAX label and is not accepted by most vehicle manufacturers as full evidence. ### Why **Is TISAX only relevant for German vehicle manufacturers?** No. TISAX is carried by the ENX Association, a non-profit organisation founded by several vehicle manufacturers, national automotive associations and suppliers in Europe. The assessment procedure is applied across Europe, and assessments are performed by assessment providers worldwide, not only in Germany. **What is the difference between ISO 27001 and TISAX?** ISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an automotive industry assessment procedure based on the VDA ISA catalogue, with a label instead of a certificate, and is contractually required by vehicle manufacturers. **What do assessment levels AL1 to AL3 mean?** AL1 is a pure self-assessment without external review and does not lead to a TISAX label. AL2 is the level typical for most participants: a remote audit by an accredited assessment provider, whose result is shared in the ENX portal. AL3 is the most comprehensive level, with an on-site audit, for particularly sensitive information or vehicle prototypes. **Do you get a public certificate with TISAX?** No. The result is stored in the ENX portal, and the assessed company shares it specifically with individual customers. There is no publicly viewable certificate as with ISO 27001. ### Obligations - Registration in the ENX portal and definition of the assessment scope (assessment objective: information security, prototype protection and/or data protection when connecting third parties) - Choice of the appropriate assessment level depending on the customer's protection needs: AL1 self-assessment without a label, AL2 remote audit by an accredited assessment provider (the standard case for most participants), AL3 on-site audit for particularly sensitive information or vehicle prototypes - Implementation of the requirements from the VDA ISA assessment catalogue - Carrying out the assessment via an assessment provider approved by ENX Penalties: No fine, since it is not a law; in practice: without a valid TISAX result, exclusion from vehicle manufacturers' supplier lists and tenders is a risk, as is termination or non-renewal of existing supply contracts. ### Evidence - TISAX result/label in the ENX portal, shared specifically with individual customers (not a public certificate as with ISO 27001) - For AL2, the result is stored in the ENX portal, visible to TISAX participants - Sharing of the result with individual customers is done by the assessed company itself in the portal Related to other norms in this knowledge base: iso27001, cra, nis2. Not evidenced / open: - The complete list of ENX members (exactly which vehicle manufacturers/associations, from which countries) was not conclusively checked in this session; enx.com/en-US/ only generally confirms 'automotive manufacturers, national automotive associations, and automotive suppliers' without a name list. - vda.de was unreachable in this session (HTTP 404 on two attempted paths); statements on the VDA ISA catalogue come exclusively from secondary sources (search results, the ENX page), not read from the VDA itself. - The exact validity period of a TISAX result and details on VDA ISA version 6.0/2027 are evidenced only from secondary sources (search result summaries), not checked against the ENX or VDA original text in this session. - The AL1/AL2/AL3 detailed description comes from secondary sources (cis-cert, kopexa, further search results), not from the ENX or VDA original text in this session. ### Sources - [TISAX — Trusted Information Security Assessment Exchange](https://enx.com/tisax) — ENX Association, retrieved 2026-09-24 (sekundaer) - [ENX Association — Übersicht](https://enx.com/en-US/) — ENX Association, retrieved 2026-09-24 (sekundaer) - [TISAX® deep dive: the three assessment levels](https://www.cis-cert.com/en/news/tisax-deep-dive-the-three-assessment-levels/) — CIS Cert (Suchergebnis), retrieved 2026-09-24 (sekundaer) - [TISAX Assessment Levels: AL1, AL2 and AL3 Compared](https://kopexa.com/en/catalog/tisax/assessment-levels) — Kopexa (Suchergebnis), retrieved 2026-09-24 (sekundaer) --- # SACOSI · Pages (full text, English) > The full text of every English page of sacosi.ch, including what is shortened or collapsible on the page itself. Each page also as Markdown under https://sacosi.ch/en/knowledge/.md, each section as JSON Lines under https://sacosi.ch/en/knowledge/seiten.en.jsonl. --- Source: https://sacosi.ch/en · As of 2026-09-24 # Situational Awareness. IT must fit the business, *not the business the IT.* SACOSI stands for Situational Awareness Consulting by Ivo Schönberner. I advise executive management, investors and family offices in Switzerland and Germany from Zürich, primarily for start-ups, scale-ups and ventures. From around ten employees, IT is no longer a laptop, but a question of regulation, risk and company value. I first capture the company's situation, then bring in the IT processes that support it, and hand over documented. 0 → 2’200 Employees at Discover Airlines supplied with IT throughout, 2021 to 2026, with a prepared handover to corporate IT. < 4 months until independent IT for FraAlliance, the joint venture between Fraport and Lufthansa. ISO 27001 · 9001 IT am Main GmbH certified since January 2025. I run the company as managing director. ZRH · FRA Zürich and Frankfurt am Main. Engagements in Switzerland and Germany. ## From ten employees, IT is no longer a laptop. I am … It is about regulation, risk and how critical the business is. And about whether IT supports the growth that executive management and investors are planning. Situational Awareness resolves this pain point, but every role feels it differently. Choose your role. What the method solves for each role is set out under [Situational Awareness](https://sacosi.ch/en/situational-awareness). ## Everyone wants something different from IT. IT has to reconcile interests that conflict with each other. As long as no one brings them onto a single page, whoever asks loudest wins. | Who | Wants | Asks | |---|---|---| | CEO | Growth and company value | Does IT support the plan for the next 24 months, and does it increase or reduce the company's value? | | CFO | Overview, control, CAPEX and OPEX matching the financing strategy | What does IT really cost, who approved it, and does the model fit our financing? | | IT management | Calm and stable operations | How do I keep operations stable while everyone wants something new at the same time? | | Quality management | Compliance | Which standard applies to us, and where is the evidence that we meet it? | | Supervisory bodies and auditors | Evidence | Can you demonstrate what you claim, versioned and approved? | | Investors | Know the risk, protect value | What IT risks am I buying into, and what does it cost to fix them? | Which standards and laws also apply, from ISO 27001 and ISO 9001 through TISAX and EU MDR to the FADP, GDPR, NIS2 and the EU AI Act, depends on the industry and markets. [Overview: Regulation](https://sacosi.ch/en/regulation) ## The situation is much more than IT. Situational Awareness does not begin with servers and software, but with what the company wants to achieve and what it can afford. Six dimensions make up the situation picture. IT is measured against them, not the other way round. L1 ### The company's goals Where does the company want to go in the next one to three years: growth, markets, profitability, exit or stability. L2 ### Leadership's vision What the board of directors, executive management and founders intend for the company, including what is not yet in any strategy document. L3 ### Core processes The processes by which the company earns its money. They determine what IT must support, not the other way round. L4 ### Financial situation Liquidity, budget, cost structure and financing stage. IT that the company cannot afford is not a solution. L5 ### Stakeholders and investors What shareholders and partners, investors, the board of directors, supervisory bodies, customers and employees expect, and where these interests conflict. L6 ### Obligations and risks Regulation, contracts, security requirements and the risks the company cannot afford. IT ### Only then: IT It is designed to meet the goals of executive management, investors and stakeholders, measurably so. Tools: SWOT analysis · process map · process flows · stakeholder, RACI and prioritisation matrix · decision log. Documented conformant to standards in an auditable system. IT is good when it meets the goals of executive management and investors. Technical elegance alone is not enough. ## Situation first. Then IT. Situational Awareness means being aware of the situation. Pilots and air traffic controllers work in three stages: perceive, understand, anticipate. I apply this to your company's situation and add the step that advisory work often lacks: implement and hand over cleanly. 01 ### Capture the situation What is really happening in the business? Company goals, leadership's vision, core processes, financial situation, the interests of investors and stakeholders, obligations. Captured from the people who run and finance the business, not in the server room. Result Situation picture, SWOT, process map 02 ### Understand the situation Where does IT help the goals, and where does it stand in the way? Every friction between goals, processes, budget and system is named, assessed by its effect on the business and finances, and brought to a decision. Result Process flows, matrices, decision log 03 ### Anticipate the situation What IT will support the business in twelve to 36 months? The target picture follows the goals of executive management and investors. Technology is chosen once it is clear what it must support and what it may cost. Result Target picture and roadmap 04 ### Lead and hand over Who will carry it once I am gone? Implement, scale, hand over cleanly: Grow. Scale. Let go. Documented in a conformant, auditable system, so that an internal team and any auditor can take over. Result Running IT, audit-proof documentation, handover Source The three-stage model goes back to Mica R. Endsley: *Toward a Theory of Situation Awareness in Dynamic Systems*, Human Factors 37(1), 1995. Step 04 is my own addition from practice: Grow. Scale. Let go. ## Strategy at executive management level. Without the overhead of a consultancy. A trusted partner for executive management and investors: strategy at executive management level, without the overhead of a consultancy. I come in, resolve the situation and hand over documented. [INVESTORS, FAMILY OFFICES, ADVISORY BOARDS Situation picture for shareholdings IT due diligence before the investment, or the situation picture in the first weeks after: risks, costs, dependencies and obligations of the shareholding on a single page, with measures ranked by effect and effort.](https://sacosi.ch/en/investors)[OWNERS BEFORE HANDOVER, BUYERS AND SUCCESSORS IT situation picture before succession The state of IT and technology, investment backlog, key-person dependencies and legacy licensing issues on a single page, as a complement to financial due diligence: prepared for handover or reviewed before purchase.](https://sacosi.ch/en/succession)[START-UPS, SCALE-UPS, VENTURES Fractional CTO for a defined period Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is handover to a permanent CTO or your own team.](https://sacosi.ch/en/fractional-cto)[EXECUTIVE MANAGEMENT, QUALITY MANAGEMENT Compliance roadmap Which standards and laws apply to your business, in what order you should address them, and how the evidence is produced in an auditable system, for example for ISO 27001, ISO 9001 or TISAX.](https://sacosi.ch/en/regulation)[GROWING COMPANIES, UP TO AROUND 1’000 EMPLOYEES Scaling architecture A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, cost in proportion to budget.](https://sacosi.ch/en/it-architecture)[CEO, CFO, BOARD OF DIRECTORS Sparring for executive management and the board A second opinion before budget is committed: platform choice, IT budget, sourcing, assessment of a proposal. Usually within a few sessions.](https://sacosi.ch/en/leadership)[CORPORATE GROUPS, JOINT VENTURES Programme leadership IT programmes with multiple shareholders: greenfield, carve-in, carve-out. Steered with evidence instead of status slides.](https://sacosi.ch/en/project-leadership) ## Where an IT outage hits the business immediately. The focus is on industries with high criticality. There, in addition to data protection and standards, separate rules apply. [ENERGY IT in energy supply Security of supply depends on control systems and networks that must not fail.](https://sacosi.ch/en/industries/energy)[MANUFACTURING IT in manufacturing A halt in production immediately costs revenue and the ability to deliver.](https://sacosi.ch/en/industries/manufacturing)[MEDTECH IT in MedTech Approval and market access depend on complete documentation.](https://sacosi.ch/en/industries/medtech)[AVIATION IT in aviation Flight operations do not forgive outages in the Operations Control Center.](https://sacosi.ch/en/industries/aviation) ## From zero to 2’200. And then letting go. In 2021, Discover Airlines had no office, no IT and no foundation, but the obligation to deliver from day one. With IT am Main, I supported the build-up: sites, workplaces, Microsoft 365, the network connectivity of the Operations Control Center. By 2026, the airline had grown to around 2’200 employees. The transition to the Lufthansa Group's corporate IT was prepared from the start. > IT am Main was never the classic service provider working through tickets, but a real sparring partner: someone who puts a finger on the sore spot, thinks along and proposes solutions before a problem becomes an outage. > > **Björn Bech** · Director Technology & Analytics, Discover Airlines ## IT first or business first? Both paths lead to working IT. Only one leads to IT that meets the goals of the company and its investors. | Question | IT first | Situational Awareness | |---|---|---| | Starting point | Which system do we need? | What do executive management and investors want to achieve in 24 months? | | Yardstick | technical best practice | goals of the company, leadership and stakeholders | | Budget | negotiated afterwards | part of the situation: liquidity and financing stage determine the architecture | | Who determines the process? | The tool and its standard processes | The core processes; the technology adapts | | Decisions | implicit, in people's heads and chats | in the decision log, traceable | | Regulation | set up afterwards | built in from the start | | End of the engagement | dependency on the advisor | documented handover to the internal team | ## The term comes from the cockpit. So does my work. Two of my largest engagements were in aviation: a new airline, a joint venture between Fraport and Lufthansa, flight operations in the Operations Control Center. There, you quickly learn that good IT must know the situation before it is needed. That applies to every company, even without aircraft. ## Short answer. The questions I am asked most often in a first conversation. ### Who is Ivo Schönberner? Ivo Schönberner is an IT entrepreneur and advisor based in Zürich and Frankfurt am Main, and managing director of IT am Main GmbH. Under the brand SACOSI, he advises executive management, investors and family offices in Switzerland and Germany on IT, risk and regulation, with a focus on start-ups, scale-ups and ventures. His advisory product is called Situational Awareness: IT derived from the situation of the business. ### What is SACOSI? SACOSI stands for Situational Awareness Consulting by Ivo Schönberner. Under this name, Ivo Schönberner offers his advisory product Situational Awareness from Zürich: IT derived from a company's goals, core processes, finances and stakeholder interests. He works as a fractional CTO, IT architect, project leader or sparring partner. ### Why does IT become a topic for executive management from ten employees? Because IT then no longer just means handing out laptops. It is about customer data and data protection, about security requirements from customers and investors, about regulation in every market where the company operates, and about costs that must fit the financing strategy. These questions decide growth and company value. ### What does SACOSI do for investors and family offices? SACOSI produces IT situation pictures and IT due-diligence reviews for shareholdings, and takes on technical leadership for a defined period where required. The principle: come in, resolve the situation, hand over documented. ### What does Situational Awareness mean in IT? Situational Awareness means being aware of the situation. The term comes from aviation and describes, according to Mica Endsley, three stages: perceiving the situation, understanding it and anticipating how it will develop. In IT, this means: first, the company's entire situation is captured, that is, goals, leadership's vision, core processes, financial situation and the interests of investors and stakeholders. Then IT is built to meet exactly these goals. ### Which companies does Ivo Schönberner work for? For executive management of start-ups, scale-ups and ventures that notice, from around ten employees, that IT becomes a leadership question. For investors and family offices whose shareholdings have IT questions. And for companies in industries with high criticality: energy, manufacturing, MedTech and aviation. He supports corporate groups and joint ventures as programme leader. ### Does Ivo Schönberner work in Switzerland and Germany? Yes. He works from Zürich and Frankfurt am Main and takes on engagements in both countries, on-site and remote, in German and English. ### How does a collaboration begin? With a 30-minute conversation without a presentation. You describe the situation, Ivo Schönberner asks questions. Afterwards, both sides know whether a situation picture makes sense and which engagement model fits. ### What distinguishes Situational Awareness from classic IT consulting? Classic IT consulting often starts with the technology and adapts the business to the system. Situational Awareness starts with the company: the goals of executive management, the expectations of investors, the core processes and the financial situation determine the architecture. At the end, there is no slide recommendation, but running IT that an internal team can take over. ## What is your situation? Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/situational-awareness · As of 2026-09-24 # IT that knows the situation of the business. **Short answer:** Situational Awareness is my advisory product. It reverses the usual order: first, the entire situation of the company is captured: company goals, the vision of the leadership, core processes, financial situation and the interests of investors and stakeholders. Only then is IT built that meets exactly these goals, thinks ahead, and strengthens the business. The end result is a running IT that your own team can take over. For executive management, investors and family offices in Switzerland and Germany, with a focus on start-ups, scale-ups and ventures. ## I am … Situational Awareness is a method, but every role has a different pain point. Choose your role: the page shows what the method solves for you, which tools help, and how you get started. CEO ### I am CEO. Does our IT carry our growth plan, and what does it do to the value of the company? **Pain** - IT slows down new locations, markets and products, and no one can say why on a single page. - In a due diligence review, gaps show up as a discount. - Larger customers demand security evidence before they sign. **What the method solves** - A situation picture on one page: which IT carries which goal. - Decision templates with options, costs and risks instead of technical reports. - Growth without IT surprises, documented for investors and buyers. **Matching tools** - **SWOT analysis:** strengths, weaknesses, opportunities and threats of the company, not of the IT. The IT questions are derived from it. - **Matrices:** stakeholder matrix by influence and interest, RACI matrix for responsibilities, prioritisation matrix by impact and effort. - **Decision log:** every decision with trigger, options, rationale, approval and date. **Download** **Situation Briefing 01** · Situational Awareness from the CEO's perspective. In preparation. **Film** [Watch film 01: Everyone wants something different (1:09)](https://sacosi.ch/en/concept#film) CFO ### I am CFO. What does IT really cost, who approved it, and does the model fit our financing? **Pain** - Contracts and subscriptions are scattered, costs show up in December instead of in the plan. - Investment or ongoing expenditure follows habit, not the exit horizon and financing strategy. - Outages, security incidents and fines feature in no plan until they happen. **What the method solves** - Every IT line item with business purpose, owner and financing form. - Approvals in the decision log, traceable for audit and the board of directors. - CAPEX and OPEX chosen deliberately: matched to exit horizon, investor type, liquidity and financing stage. **Matching tools** - **Decision log:** every decision with trigger, options, rationale, approval and date. - **Matrices:** stakeholder matrix by influence and interest, RACI matrix for responsibilities, prioritisation matrix by impact and effort. - **Process map:** management, core and support processes on one page. Shows which activities earn the money and what the IT has to carry. **Download** **Situation Briefing 02** · Situational Awareness from the CFO's perspective. In preparation. **Film** [Watch film 01: Everyone wants something different (1:09)](https://sacosi.ch/en/concept#film) Investor / Family Office ### I am an investor or family office. Which IT risks am I buying into, and what does it cost to fix them? **Pain** - A holding has IT questions, and no one in the company has an overview of the situation. - A large consultancy is too heavy for the question. - IT risks and costs across different holdings are not comparable. - It is unclear whether capitalised IT investments (CAPEX) in a holding are even reflected at exit, or whether they weigh on the multiple instead. **What the method solves** - IT due diligence before entry, situation picture in the first weeks after. - Measures prioritised by value impact and effort. - Come in, resolve, hand over documented, without lasting dependency on the advisor. - Clarity on whether a holding operates conformant or is certified, and what the difference is worth in a due diligence review. **Matching tools** - **SWOT analysis:** strengths, weaknesses, opportunities and threats of the company, not of the IT. The IT questions are derived from it. - **Matrices:** stakeholder matrix by influence and interest, RACI matrix for responsibilities, prioritisation matrix by impact and effort. - **Auditable documentation:** conformant, for example with ISO 27001 and ISO 9001: versioned, with approvals and evidence, in a system an auditor can review. **Download** **Situation Briefing 03** · Situational Awareness from the investor's perspective. In preparation. **Film** Film 02 · The investor asks about IT. In production. IT management ### I lead the IT. How do I keep operations stable while everyone wants something new at the same time? **Pain** - Requirements from executive management, business units and customers conflict with each other. - Knowledge sits in individual heads, cover is difficult. - Priorities lack backing from executive management. - Development, test and production are not cleanly separated, and every change is a risk to ongoing operations. **What the method solves** - Priorities that executive management backs, because they are derived from the situation. - A target architecture that carries the planned growth. - Documentation that makes operations, cover and handover possible. - Separate development, test and production systems, and tenant separation from the start, instead of an expensive rebuild later. **Matching tools** - **Process flows:** the critical activities in detail, with roles, handovers, systems and media breaks, for example in BPMN notation. - **Matrices:** stakeholder matrix by influence and interest, RACI matrix for responsibilities, prioritisation matrix by impact and effort. - **Auditable documentation:** conformant, for example with ISO 27001 and ISO 9001: versioned, with approvals and evidence, in a system an auditor can review. **Download** **Situation Briefing 04** · Situational Awareness from the perspective of IT management. In preparation. **Film** [Watch film 01: Everyone wants something different (1:09)](https://sacosi.ch/en/concept#film) QM / Compliance ### I am responsible for quality and compliance. Which standard applies to us, and where is the evidence that we meet it? **Pain** - Standards and laws from several countries overlap. - Evidence sits in chats, folders and people's heads. - The next audit is coming up. **What the method solves** - An obligations list by industry, market and activity. - A roadmap sequenced by risk and business impact. - Evidence versioned and approved, in an auditable system. **Matching tools** - **Auditable documentation:** conformant, for example with ISO 27001 and ISO 9001: versioned, with approvals and evidence, in a system an auditor can review. - **Decision log:** every decision with trigger, options, rationale, approval and date. - **Process map:** management, core and support processes on one page. Shows which activities earn the money and what the IT has to carry. **Download** **Situation Briefing 05** · Situational Awareness from the perspective of QM and compliance. In preparation. **Film** Film 03 · The audit is coming. In production. Founder / Scale-up ### I am founding or running a scale-up. From what point is IT more than buying laptops for us? **Pain** - From around ten employees, IT no longer fits in one head. - Customers and investors ask about security and data protection. - What is built today for twenty people has to carry a hundred in a year. - Development, test, production and customer tenants grow together under time pressure, instead of being separated from the start. **What the method solves** - IT processes that grow with the company, without legacy issues. - Knowing early which regulations come with new markets and customers. - Interim technical leadership, until a permanent CTO takes over. - Separate environments and tenant separation from the start, before a rebuild becomes expensive. **Matching tools** - **Process map:** management, core and support processes on one page. Shows which activities earn the money and what the IT has to carry. - **Decision log:** every decision with trigger, options, rationale, approval and date. - **SWOT analysis:** strengths, weaknesses, opportunities and threats of the company, not of the IT. The IT questions are derived from it. **Download** **Situation Briefing 06** · Situational Awareness from the perspective of founders and scale-ups. In preparation. **Film** Film 04 · From ten people, IT is no longer a laptop. In production. Succession / Handover ### I am facing a succession, handover or acquisition. What does a successor or buyer really take on if they cannot see the IT? **Pain** - A successor or buyer has no picture of the state of the IT and technology, of the investment backlog, licence and contract legacy. - A financial due diligence review checks figures, not whether the company depends on individual people and their undocumented knowledge. - Security legacy issues and dependency on individual providers only become visible after the handover, once no one can ask any more. **What the method solves** - IT situation picture before the handover: condition, risks and investment backlog on one page, for both the party handing over and the buyer. - Technical due diligence as a complement to the financial one: what the balance sheet does not show. - Key-person dependency map: which knowledge is tied to which person, and what documenting it costs. **Matching tools** - **Process map:** management, core and support processes on one page. Shows which activities earn the money and what the IT has to carry. - **Matrices:** stakeholder matrix by influence and interest, RACI matrix for responsibilities, prioritisation matrix by impact and effort. - **Auditable documentation:** conformant, for example with ISO 27001 and ISO 9001: versioned, with approvals and evidence, in a system an auditor can review. **Download** **Situation Briefing 07** · Situational Awareness from the succession perspective. In preparation. **Film** Film 05 · The buyer asks who knows the password. In production. ## What does Situational Awareness mean in IT? Situational Awareness means being aware of the situation: knowing what is happening around you, what it means, and how it will develop. The term comes from aviation. The researcher Mica R. Endsley described it in 1995 in three stages: - **Perceiving**: recognising the elements of a situation - **Understanding**: grasping what they mean together - **Projecting**: deriving how the situation will develop Pilots, air traffic controllers and control centres train exactly these three stages, because errors rarely arise from a lack of technology, but from a wrong picture of the situation. IT is no different. Many projects fail not because of software or budget, but because no one understood the situation of the business before building anything. Situational Awareness transfers the three stages to the situation of a company, that is, to goals, leadership, processes, finances and stakeholders, derives the IT from that, and adds a fourth stage: implement and hand over. ## What belongs to the situation of a company? The situation covers far more than IT: goals, vision, core processes, finances, stakeholders and obligations. IT is not part of the situation; it is measured against it. L1 ### Company goals Where the company wants to be in the next one to three years: growth, markets, profitability, exit or stability. L2 ### Vision of the leadership What the board of directors, executive management and founders intend for the company, including what is not yet in any strategy paper. L3 ### Core processes The activities with which the company earns its money. They determine what the IT has to carry, not the other way round. L4 ### Financial situation Liquidity, budget, cost structure and financing stage. An IT that the company cannot afford is not a solution. L5 ### Stakeholders and investors What shareholders and members, investors, the board of directors, supervisory bodies, customers and employees expect, and where these interests conflict. L6 ### Obligations and risks Regulation, contracts, security requirements and the risks the company cannot afford. From this follows the yardstick for every IT decision: **Does it meet the goals of executive management and investors, and can the company afford it?** A technically elegant solution that misses the goals or overstretches liquidity is not, in this sense, good IT. This also includes the financing form: whether an IT investment is capitalised as CAPEX or expensed as OPEX follows no fixed rule, but the exit horizon, the valuation logic and the investor type. More on this under [Executive management](https://sacosi.ch/en/leadership#finanzierung). Where interests conflict, for example the investors' pace of growth against security requirements, or budget limits against the founders' vision, the conflict is not concealed technically but put forward openly for a decision. ## Which interests must IT reconcile? The interests of the CEO, the CFO, IT management, quality management, supervisory bodies and investors. They often conflict, and that is exactly why they belong on one page. ### CEO: growth and company value Does the IT carry the plan for the next 24 months, and does it increase or reduce the value of the company? ### CFO: overview, control, CAPEX and OPEX matched to the financing strategy What does IT really cost, who approved it, and does the model fit our financing? ### IT management: calm and stable operations How do I keep operations stable while everyone wants something new at the same time? ### Quality management: compliance Which standard applies to us, and where is the evidence that we meet it? ### Supervisory bodies and auditors: evidence Can you prove what you claim, versioned and approved? ### Investors: know the risk, protect the value Which IT risks am I buying into, and what does it cost to fix them? In addition, there are standards and laws depending on industry and market: ISO 27001 and ISO 9001, TISAX in the automotive supply chain, the medical device regulations of Switzerland and the EU, the Swiss Federal Act on Data Protection, the GDPR, NIS2 and the EU AI Act. The classification is set out under [Regulation](https://sacosi.ch/en/regulation). ## IT has to fit the business, not the business the IT. When a company adapts its activities to a system, it pays for it every day: with workarounds, shadow lists and dependency on individual people. Typical signs that the business is being forced into the IT: - Alongside the official system, employees keep their own lists, because the real process is not reflected there. - Processes are rebuilt because a tool demands it, not because the business needs it. - Decisions about IT are made in chats and in people's heads and can no longer be traced a year later. - Regulation such as ISO 27001, the Swiss Federal Act on Data Protection (FADP), the GDPR or industry requirements is bolted onto the IT after the fact. - No one can explain on one page which IT carries which business goal. An IT with situational awareness reverses this. It is derived from the activities, knows the company's obligations from the outset, and adapts as the business changes. ## How does an engagement proceed? An engagement has four steps. Each ends with a result you keep, even if we do not continue working together afterwards. 01 · Situation picture, SWOT, process map ### Capture the situation What is really happening in the business? Company goals, vision of the leadership, core processes, financial situation, interests of investors and stakeholders, obligations. Captured from the people who run and finance the business, not in the server room. 02 · Process flows, matrices, decision log ### Understand the situation Where does the IT help the goals, and where does it stand in the way? Every point of friction between goals, processes, budget and system is named, assessed by its impact on the business and finances, and brought to a decision. 03 · Target picture and roadmap ### Project the situation forward Which IT carries the business in twelve to 36 months? The target picture follows the goals of executive management and investors. Technology is chosen once it is clear what it has to carry and what it may cost. 04 · Running IT, audit-ready documentation, handover ### Lead and hand over Who carries it once I leave? Implement, scale, hand over cleanly: Grow. Scale. Let go. Documented conformant in an auditable system, so that an internal team and any auditor can take over. ## Which tools are used to capture the situation? With tools that executive management and investors know, not IT jargon. Every result is documented conformant and auditable. ### SWOT analysis Strengths, weaknesses, opportunities and threats of the company, not of the IT. The IT questions are derived from it. ### Process map Management, core and support processes on one page. Shows which activities earn the money and what the IT has to carry. ### Process flows The critical activities in detail, with roles, handovers, systems and media breaks, for example in BPMN notation. ### Matrices Stakeholder matrix by influence and interest, RACI matrix for responsibilities, prioritisation matrix by impact and effort. ### Decision log Every decision with trigger, options, rationale, approval and date. ### Auditable documentation Conformant, for example with ISO 27001 and ISO 9001: versioned, with approvals and evidence, in a system an auditor can review. The documentation is not an appendix at the end; it arises with every step. It sits in an auditable system, versioned, with approvals and evidence. What that looks like in practice is shown by IT am Main itself: the company has been certified to ISO 27001 and ISO 9001 since January 2025. ## What do you get in the end? Not a slide collection, but working tools your company continues to use. - **Situation picture on one page:** company goals, vision of the leadership, core processes, financial situation, interests of investors and stakeholders, obligations, and the current IT, so that executive management understands it in five minutes. - **Fit analysis:** where the IT carries the goals of leadership and investors and where it does not, each with impact on business and finances and with effort. - **Decision log:** every architecture decision with trigger, options, rationale and date. - **Target picture and roadmap:** which IT carries the business in twelve to 36 months and in what order it is built. - **SWOT, process map, process flows and matrices:** the working basis on which leadership, business units and IT see the same situation. - **Auditable documentation:** conformant, versioned and approved, reviewable for auditors and investors. - **Handover:** an operations manual and a team that runs the IT without me. - **Playbooks (documented procedures, SOPs):** runbooks, SOPs, handover documentation and contingency procedures with which the internal team runs operations without an advisor. Target picture, roadmap and decision log together form the game plan. ## Who is Situational Awareness for? For companies where IT and business are drifting apart, and for everyone who has to answer for that. - **Executive management** wondering why they should concern themselves with IT: the CEO looking at growth and company value, the CFO looking at cost, control and financing strategy. [For executive management](https://sacosi.ch/en/leadership). - **Investors and family offices** whose holdings have IT questions and who need someone to come in, resolve them, and leave again. [For investors](https://sacosi.ch/en/investors). - **Start-ups, scale-ups and ventures** that notice, from around ten employees, that IT is no longer a laptop. [IT for scale-ups](https://sacosi.ch/en/scale-ups). - **Quality management and compliance** that need evidence for standards and laws. [Regulation](https://sacosi.ch/en/regulation). - **Industries with high criticality:** energy, manufacturing, MedTech and aviation. [Industries](https://sacosi.ch/en/industries). - **Corporate groups and joint ventures** with complex IT programmes: [Project leadership](https://sacosi.ch/en/project-leadership). And, in its shortest form, sparring: an independent second opinion before a decision, usually over a few sessions. ## What Situational Awareness is not - **Not a tool.** No software is sold. The technology follows the situation. - **Not a certificate.** I use standards such as ISO 27001 or ITIL where they serve the business, not as an end in themselves. - **Not a standing engagement.** The goal is the handover. In the best case, I make myself redundant. - **Not taking over responsibility.** Your company makes the decisions. I prepare them, document them and implement them. ## Where the method comes from Situational Awareness grew out of engagements in which IT had to deliver under time pressure and regulation. At Discover Airlines, IT am Main built the IT from scratch from 2021 and carried it through growth to around 2’200 employees, including the network connection of the Operations Control Center, with the handover to the Lufthansa Group's corporate IT prepared in advance (2021 to 2026). For FraAlliance, the joint venture of Fraport and Lufthansa, an independent IT connecting two corporate worlds was built in under four months. IT am Main, the company I run as managing director, implemented both. ## Terms - **Situational Awareness:** perceiving, understanding and projecting a situation (Endsley 1995). Here: the name of the advisory product. - **Situation picture:** a one-page representation of the six dimensions of a company (goals, vision of the leadership, core processes, financial situation, stakeholders and investors, obligations and risks) and the current IT. - **Fit analysis:** a comparison of where the IT meets the goals of the company and its stakeholders and where friction arises. - **Stakeholder:** everyone with a legitimate interest in the company: shareholders and members, investors, executive management, supervisory bodies, customers, employees. - **Decision log:** an ongoing record of all architecture decisions with rationale, also known as an Architecture Decision Record (ADR). - **Fractional CTO:** technical leadership on a part-time or interim basis, typically for start-ups and scale-ups without a permanent CTO. - **SWOT analysis:** Strengths, Weaknesses, Opportunities, Threats: the strengths, weaknesses, opportunities and threats of a company. - **Process map:** an overview of all management, core and support processes of a company on one page. - **RACI matrix:** an assignment of who is responsible for a task (Responsible), who decides (Accountable), who is involved (Consulted) and who is informed (Informed). - **Auditable documentation:** documentation kept to a standard such as ISO 27001 or ISO 9001: versioned, approved, with evidence and reviewable for auditors. - **Grow. Scale. Let go.:** build up, scale, hand over: the guiding theme for step 04. - **Playbooks (documented procedures, SOPs):** documented IT and operational procedures: runbooks, SOPs, handover documentation and contingency procedures, so that an internal team can run operations without an advisor. ## Sources - Endsley, M. R. (1995). Toward a Theory of Situation Awareness in Dynamic Systems. *Human Factors*, 37(1), 32–64. (independent research) - Reference cases Discover Airlines and FraAlliance, released by the customers for IT am Main, as of June 2026. (own source) ## Questions about Situational Awareness. ### What is the advisory product Situational Awareness? Situational Awareness is Ivo Schönberner's advisory product. It aligns a company's IT with the entire situation, that is, with company goals, the vision of the leadership, core processes, the financial situation and the interests of investors and stakeholders: in four steps, from capturing the situation through the fit analysis and the target picture to implementation and handover to an internal team. ### What belongs in a situation picture under Situational Awareness? Six dimensions: the company's goals, the vision of the leadership, the core processes, the financial situation, the interests of investors and other stakeholders, and obligations and risks. IT is deliberately not part of the situation; it is measured against it. ### Why does the financial situation belong in an IT advisory engagement? Because IT ties up money and can save money. Liquidity, budget, cost structure and financing stage determine which architecture is viable. A technically ideal solution that overstretches the company financially does not meet the goals of executive management. ### How does Situational Awareness take investors and stakeholders into account? Their expectations are explicitly captured in the situation picture, for example growth goals, exit readiness, due-diligence maturity or requirements from shareholders. The IT is designed to support these goals measurably, and conflicting goals between stakeholders are put forward openly for a decision. ### Which tools does Situational Awareness work with? With proven management tools instead of IT jargon: a SWOT analysis of the company, a process map, process flows of the core processes (for example in BPMN), stakeholder, RACI and prioritisation matrices, and a decision log. The target picture and roadmap for the IT are derived from these. ### How is the documentation made audit-ready? All results are kept conformant, for example to the requirements of ISO 27001 and ISO 9001: versioned, with approvals, owners and evidence, in an auditable system instead of scattered files. This lets an auditor trace every decision, even after the handover. ### Where does the term Situational Awareness come from? From aviation and human-factors research. Mica R. Endsley defined situational awareness in 1995 as the perception of the elements of a situation, the comprehension of their meaning, and the projection of their future status. Pilots and air traffic controllers train exactly these three stages. ### How can you tell that the business is being forced into the IT? Typical signs: employees keep shadow lists alongside the system, processes are rebuilt because a tool demands it, decisions hang on individual people, and no one can explain on one page which IT carries which business goal. ### What do you get at the end of an engagement? A situation picture on one page, a fit analysis with a decision log, a target picture with a roadmap and, if desired, the implemented IT with a documented handover to the internal team, including playbooks (documented procedures, SOPs) for operations and contingencies. ### How long does a situation picture take? That depends on size, locations and regulation. Scope and timeframe are set in the initial conversation and fixed in writing afterwards. ### Is Situational Awareness a framework or a certification? No. It is a way of working with defined results. Existing standards such as ISO 27001 or ITIL are used where they serve the business, but not introduced as an end in themselves. ### For which company sizes is Situational Awareness suitable? From a start-up with ten people to a company with around 1’000 employees, plus programmes in corporate groups and joint ventures. What matters is not the size, but that IT and business are drifting apart. ### Who bears responsibility during the engagement? Responsibility for decisions stays with the company. Ivo Schönberner prepares decisions, documents them in the decision log, and implements what is decided. ### Does Ivo Schönberner work independently of vendors? Yes. The technology follows the business. Microsoft 365, Mac and Windows, cloud or locally run AI are chosen for fit, not for partner status. ### What does Situational Awareness cost? There is no off-the-shelf package. Billing is by day rate or monthly engagement, depending on the engagement model and scope. You clarify the framework in the first conversation. ## How is your situation? Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/concept · As of 2026-09-24 # Situational Awareness. IT that knows the situation. ## The film series. Four films, each about one minute. Film 01 · Everyone wants something different Film 01 Everyone wants something different CEO, CFO, IT and staff: four interests, one IT. 1:09 · play Film 02 The investor asks about IT Due diligence: what an investor wants to know about IT. approx. 1:00 · in production Film 03 The audit is coming Quality management, auditor and the question of evidence. approx. 1:00 · in production Film 04 From ten people, IT is no longer a laptop Growth, regulation, CAPEX and OPEX. approx. 1:00 · in production Film 05 The buyer asks who knows the password Succession: what a buyer does not see about IT before signing. approx. 1:00 · in production ### Transcript: Everyone wants something different - **Mara, IT:** I'm Mara. I do IT here. And everyone wants something different from me. - **Daniel, CEO:** Mara, next year we're opening two new branches. We can make that work, right? - **Mara:** He's not talking about laptops. He's talking about the company. - **Sandra, CFO:** And what's the cost? This time up front, please - not in December. - **Mara:** Sandra doesn't want technology. She wants predictability. - **Jonas, Shipping:** I just want to ship packages. Not type everything twice. - **Mara:** Fair. - **Mara:** Those aren't IT wishes. That's the company's situation. And IT has to fit that - not the other way round. - **Mara:** So we build a situation picture. All interests on one page. - **Jonas:** Oh, that actually works. - **Mara:** That's called Situational Awareness. Situation first. Then IT. Films created with AI assistance. Characters, voices and companies are fictional. ## What it is. When a company adapts to its IT, something is the wrong way round. Situational Awareness reverses that. First comes the company's situation, with its goals, its finances and the expectations of its investors. Then comes IT that meets exactly that. ## Situational Awareness. In numbers. ### Dimensions Goals, vision, core processes, finances, stakeholders, obligations. Every IT is measured against these. ### Steps Capture, understand, anticipate, lead and hand over. 0 → 2’200 ### Employees Discover Airlines, 2021 to 2026, carried throughout by IT am Main. < 4 ### Months until independent IT for FraAlliance, the joint venture between Fraport and Lufthansa. 1995 ### Endsley The three-stage model of Situational Awareness from human factors research. ## The situation is more than IT. Six dimensions make up the situation picture. IT is measured against them, not the other way round. L1 The company's goals L1 ### The company's goals Where does the company want to go in the next one to three years: growth, markets, profitability, exit or stability. L2 ### Leadership's vision What the board of directors, executive management and founders intend for the company, including what is not yet in any strategy document. L3 ### Core processes The processes by which the company earns its money. They determine what IT must support, not the other way round. L4 ### Financial situation Liquidity, budget, cost structure and financing stage. IT that the company cannot afford is not a solution. L5 ### Stakeholders and investors What shareholders and partners, investors, the board of directors, supervisory bodies, customers and employees expect, and where these interests conflict. L6 ### Obligations and risks Regulation, contracts, security requirements and the risks the company cannot afford. IT ### Only then: IT. It is designed to meet the goals of executive management, investors and stakeholders, and so that the company can afford it. ## Four steps. One result that lasts. 01 ### What is really happening in the business? Company goals, leadership's vision, core processes, financial situation, the interests of investors and stakeholders, obligations. Captured from the people who run and finance the business, not in the server room. Result Situation picture, SWOT, process map 02 ### Where does IT help the goals, and where does it stand in the way? Every friction between goals, processes, budget and system is named, assessed by its effect on the business and finances, and brought to a decision. Result Process flows, matrices, decision log 03 ### What IT will support the business in twelve to 36 months? The target picture follows the goals of executive management and investors. Technology is chosen once it is clear what it must support and what it may cost. Result Target picture and roadmap 04 ### Who will carry it once I am gone? Implement, scale, hand over cleanly: Grow. Scale. Let go. Documented in a conformant, auditable system, so that an internal team and any auditor can take over. Result Running IT, audit-proof documentation, handover ## Tools executive management already knows. No IT jargon. And everything documented in a conformant, auditable system. ### SWOT analysis Strengths, weaknesses, opportunities and threats of the company, not of IT. The IT questions are derived from this. ### Process map Management, core and support processes on a single page. Shows which processes earn the money and what IT must support. ### Process flows The critical processes in detail, with roles, handovers, systems and media breaks, for example in BPMN notation. ### Matrices Stakeholder matrix by influence and interest, RACI matrix for responsibilities, prioritisation matrix by effect and effort. ### Decision log Every decision with its trigger, options, rationale, approval and date. ### Auditable documentation Maintained conformant to standards, for example ISO 27001 and ISO 9001: versioned, with approvals and evidence, in a system an auditor can examine. ## Real engagements. Real impact. Discover Airlines · 2021 to 2026 ### From zero to around 2’200 employees. IT built up from an empty office, network connectivity for the Operations Control Center, a handover to the Lufthansa Group's corporate IT prepared from the start. Delivered with IT am Main. FraAlliance · 2022 ### Independent IT in under four months. Two corporate worlds connected, central identity, compliance requirements of the Lufthansa Group. Delivered with IT am Main. ## One concept. Four engagement models. [Fractional CTO Start-ups and scale-ups Find out more](https://sacosi.ch/en/fractional-cto)[IT Architect Companies up to 1’000 employees Find out more](https://sacosi.ch/en/it-architecture)[Project Leader Enterprise, corporate groups, joint ventures Find out more](https://sacosi.ch/en/project-leadership)[Sparring Partner Boards of directors, executive management, investors Find out more](https://sacosi.ch/en/situational-awareness#sparring) ## The next step. Thirty minutes, no presentation. You describe the situation, I ask questions. ### Book a call Choose a slot directly in my calendar. ### Write an email Describe the situation in a few sentences, I reply personally. ### Call Zürich +41 78 251 09 69Frankfurt +49 152 27602667 ## Questions? Answers. ### What is the advisory product Situational Awareness? Situational Awareness is Ivo Schönberner's advisory product. It aligns a company's IT with its entire situation, that is, with company goals, leadership's vision, core processes, financial situation and the interests of investors and stakeholders: in four steps, from capturing the situation through the fit analysis and the target picture to implementation and handover to an internal team. ### What belongs in a situation picture under Situational Awareness? Six dimensions: the company's goals, leadership's vision, the core processes, the financial situation, the interests of investors and other stakeholders, and obligations and risks. IT is deliberately not part of the situation, but is measured against it. ### Why does the financial situation belong in IT advisory work? Because IT ties up money and can save money. Liquidity, budget, cost structure and financing stage decide which architecture is viable. A technically ideal solution that overburdens the company financially does not meet executive management's goals. ### How does Situational Awareness take investors and stakeholders into account? Their expectations are explicitly captured in the situation picture, for example growth targets, exit readiness, due-diligence readiness or requirements set by shareholders. IT is designed to support these goals measurably, and conflicting goals between stakeholders are put forward openly for a decision. ### What tools does Situational Awareness work with? With proven management tools instead of IT jargon: a SWOT analysis of the company, a process map, process flows of the core processes (for example in BPMN), stakeholder, RACI and prioritisation matrices, and a decision log. From these, the target picture and roadmap for IT are derived. ### How does the documentation become audit-proof? All results are maintained conformant to standards, for example to the requirements of ISO 27001 and ISO 9001: versioned, with approvals, owners and evidence, in an auditable system instead of scattered files. This allows an auditor to trace every decision, even after the handover. --- Source: https://sacosi.ch/en/leadership · As of 2026-09-24 # Why you should care about IT as CEO or CFO. **Short answer:** Because from around ten employees onwards, IT co-determines how fast your company can grow, what it is worth and what it costs. The CEO asks about growth and company value, the CFO about oversight, control and the right ratio of investment to ongoing expenditure. I bring both questions together into one situation picture and prepare the decisions so that you can make them without being a technology expert. ## Why one page for CEO and CFO together? Because the two questions only have an answer together: growth costs money, and cost control without a growth plan saves in the wrong place. In almost every IT decision, the interests of the CEO and the CFO collide. Viewed separately, the louder side wins. In the situation picture, both sit side by side, together with the interests of IT management, quality management, oversight and investors. | Who | Wants | Asks | |---|---|---| | CEO | Growth and company value | Does the IT support the plan for the next 24 months, and does it increase or reduce the value of the company? | | CFO | Oversight, control, CAPEX and OPEX matching the financial strategy | What does IT really cost, who approved it, and does the model fit our financing? | | IT management | Calm and stable operations | How do I keep operations stable while everyone wants something new at the same time? | | Quality management | Compliance | Which standard applies to us, and where is the evidence that we meet it? | | Oversight and auditors | Evidence | Can you prove what you claim, versioned and approved? | | Investors | Know the risk, protect value | Which IT risks am I buying into, and what does it cost to fix them? | ## What does IT have to do with growth and company value? IT co-determines whether a growth plan can be implemented on time and whether a review by investors or buyers ends without a discount. - **Speed:** New locations, markets and products only launch as fast as identities, workplaces, data and processes can keep up. - **Value:** In a due diligence, knowledge held by individuals, missing evidence and outdated systems stand out as risks. - **Customers:** Larger customers demand security evidence before they sign. - **Markets:** Every new market brings its own rules, from data protection to industry regulations. - **Evidence:** Working in a conformant way is not the same as being certified. In supplier assessments and customers' security questionnaires, the difference still matters a great deal, because a certificate creates trust without a review of your own. ## How does a CFO gain control over IT costs? With an overview that assigns every IT item to a business purpose, an owner and a form of financing. - **Overview:** all contracts, licences and services in one place, with term and notice period. - **Control:** approvals in the decision log, traceable for audit and the board of directors. - **CAPEX and OPEX:** whether investment or ongoing expenditure, decided by exit horizon, investor type, liquidity and financing stage, not by habit. - **Risk:** outages, security incidents and fines as a cost item, before they occur. ## CAPEX or OPEX: what fits our financing? There is no fixed rule. The choice depends on exit horizon, valuation logic, liquidity and investor type. In a valuation based on EBITDA multiples, ongoing expenditure (OPEX) reduces EBITDA and therefore tends to reduce the multiple value, whereas capitalised investments (CAPEX) do not directly burden EBITDA. CAPEX, however, ties up liquidity, burdens free cash flow and creates assets with their own useful life that a buyer shortly before an exit often does not pay for in full, or discounts in due diligence. The IT still has to meet the requirements of the business and remain robust, regardless of how it is financed. ### Short exit horizon, exit-oriented investor Tendency OPEX. Depends on: whether a buyer pays for the investment, the effect on EBITDA under the multiple, the lock-in an investment creates. ### Short exit horizon, long-term-oriented investor (e.g. a family office with no pressure to exit) Weigh up. Depends on: whether the platform holds beyond the point of exit and who remains the owner afterwards. ### Long investment horizon, exit planned only in several years Weigh up. Depends on: the valuation method at the actual point of exit (multiple, free cash flow or substance) and the condition of the assets at the time of sale. ### Long investment horizon, long-term-oriented investor CAPEX negotiable. Depends on: liquidity, useful life of the platform, effect on free cash flow. This assessment does not replace a conversation with your fiduciary services provider or your CFO. It shows which questions need to be clarified before the decision. ## Which support fits your situation? ### [Fractional CTO for a defined period](https://sacosi.ch/en/fractional-cto) Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is the handover to a permanent CTO or your own team. ### [Compliance roadmap](https://sacosi.ch/en/regulation) Which standards and laws apply to your business, in what order you should address them, and how the evidence is created in an auditable system, for example for ISO 27001, ISO 9001 or TISAX. ### [Scaling architecture](https://sacosi.ch/en/it-architecture) A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, cost in proportion to the budget. ### [Sparring for executive management and the board of directors](https://sacosi.ch/en/leadership) The second opinion before budget is committed: platform choice, IT budget, sourcing, assessment of a project. Usually in a few sessions. All offerings follow the same method: Situational Awareness. The situation first, then the IT. The method from the perspective of the [CEO](https://sacosi.ch/en/situational-awareness?rolle=ceo#ceo) and from the perspective of the [CFO](https://sacosi.ch/en/situational-awareness?rolle=cfo#cfo). ## Questions from executive management. ### Why should a CEO care about IT? Because from a certain size onwards, IT co-determines how fast the company can grow and what it is worth. Whether new locations, markets or products launch on time, whether customer data is secure and whether a due diligence goes through without a discount depends on decisions that would otherwise be made without executive management. ### Why should a CFO care about IT? Because IT ties up money, creates ongoing costs and carries risks that appear on no balance sheet until they occur. Whether a solution is financed as an investment (CAPEX) or as ongoing expenditure (OPEX) belongs to the financial strategy, not just to procurement. ### What does a situation picture give executive management? One page on which goals, core processes, finances, stakeholders, obligations and the current IT stand together. Executive management sees which IT supports which goal, where the risks lie and which decision is next. ### Do we need a full-time CIO or CTO for this? Not necessarily. Many growing companies need leadership capacity for a defined period: clarify the situation, set the direction, put the team and partners in place, and then hand over. That is the core of a fractional CTO engagement. ### How does Ivo Schönberner report to executive management and the board of directors? With decision papers instead of technical reports: occasion, options, costs, risks and recommendation, recorded in the decision log. The decision stays with executive management. ### Should we plan IT as CAPEX or OPEX before an exit? That depends on the exit horizon, the valuation logic and the investor type, not on a fixed rule. With a short exit horizon, you avoid investments that a buyer often does not pay for, and you manage the effect on EBITDA deliberately, because a multiple-based valuation treats ongoing expenditure differently from capitalised investments. With a long-term investor, CAPEX for a platform that holds for years is negotiable. The financial strategy sets this framework, not IT alone. ### What is the difference between conformant and certified? Conformant means that procedures and evidence meet the substantive requirements of a standard such as ISO 27001 or ISO 9001. Certified means that an external auditor has formally confirmed this. For your own management, conformity may be enough; in supplier assessments and customers' security questionnaires, however, a certificate often makes the difference as to whether a tender proceeds at all. ## What is the situation in your executive management? Thirty minutes, no pitch. You describe the situation, I ask questions. After that, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/investors · As of 2026-09-24 # IT situation picture and due diligence for investments. **Short answer:** When an investment has IT questions, you need someone who comes, clarifies the situation, resolves what is necessary and leaves again. I review the IT before the investment, produce a situation picture with measures after the investment, and take on technical leadership for a defined period if needed. At the level of a strategy consultancy, without its overhead, with a focus on Switzerland and Germany. ## When does an investment need an IT expert for a defined period? When IT affects the value of the investment and no one in the company has full oversight of the situation. ### Before the investment The IT due diligence shows which risks and costs you are buying into. ### After the investment The situation picture gives management a plan for the first months. ### During growth New markets, locations or customers bring requirements that the IT does not yet meet. ### Before the exit Evidence, documentation and architecture are prepared so that buyers can review them. An investment purchase is, for the target company, also a succession situation: the previous owner or managing director hands over responsibility, and the IT is no longer looked after by the same people as before. Where investment backlog, key-person dependencies or legacy licensing issues play a role, the same review applies as for a [business succession](https://sacosi.ch/en/succession). ## What does an IT due diligence examine? Whether the IT can support the business model and the growth plan, and what it costs if it cannot. - **Architecture and scalability:** does the technology support the planned growth, or does it break at the next order of magnitude? - **Security and access:** demonstrated rather than asserted, with roles, permissions and incidents. - **Costs:** current costs, costs under growth, contracts and terms. - **Dependencies:** on individual people, providers and legacy systems. - **Obligations:** data protection, industry regulations, standards and customer requirements by market. An overview is available under [Regulation](https://sacosi.ch/en/regulation). Here, the difference between conformant and certified matters: conformant means that procedures and evidence meet the substantive requirements of a standard such as ISO 27001, certified means that an external auditor has formally confirmed this. In due diligence reviews, supplier assessments and customers' security questionnaires, this difference accounts for a large part of the value. - **Documentation:** verifiable in a system, or only in people's heads. ## How do CAPEX or OPEX in IT affect the value of an investment? There is no fixed rule. The effect depends on the exit horizon of the investment, the valuation logic and the investor type. In a valuation based on EBITDA multiples, ongoing expenditure (OPEX) reduces EBITDA and therefore tends to reduce the multiple value, whereas capitalised investments (CAPEX) do not directly burden EBITDA. CAPEX, however, ties up liquidity, burdens free cash flow and creates assets with their own useful life that a buyer shortly before an exit often does not pay for in full, or discounts in due diligence. With a short exit horizon, it is therefore worth examining the investment's IT investments against exactly this question; with a long-term investment horizon, CAPEX for a platform that carries the business can make sense. This assessment belongs in the investment's IT situation picture, not in a blanket rule. More on this trade-off, from the CFO's perspective, under [Executive management](https://sacosi.ch/en/leadership#finanzierung). ## What do investors get at the end? A situation picture on one page and a list of measures, ordered by effect on value and by effort. - Findings classified by risk and urgency - Measures with effort, sequence and owners - a decision log that management and the advisory board continue to maintain - on request, implementation as [Fractional CTO](https://sacosi.ch/en/fractional-cto), until management takes over ## What does trusted partner mean for investors? Independent, at executive-management level, with no interest in a permanent engagement. - **Come, resolve, leave:** the engagement has a start, a goal and a handover. - **Vendor-independent:** the technology follows the business, not a partner status. - **Modern technology without legacy baggage:** built to scale, so that the next round does not start with a rebuild. - **Documented:** every decision versioned and approved, verifiable for auditors and buyers. Evidenced in practice: at Discover Airlines, IT am Main built the IT from zero starting in 2021 and carried it through growth to around 2’200 employees, with a prepared handover to the Lufthansa Group's corporate IT. ## Questions from investors. ### What is an IT due diligence? IT due diligence examines, before or after an investment, whether a company's IT can support the business model and the growth plan. It assesses architecture, security, costs, dependencies on people and providers, and regulatory obligations, and quantifies what is needed to resolve the findings. ### When is an IT situation picture worthwhile for an investment? Before the investment, when IT can be a value driver or a risk. In the first weeks after the investment, when management needs a plan. And whenever an investment grows, enters new markets or becomes regulated. ### What does "come, resolve, leave" mean? I take on a clearly defined engagement in the investment, clarify the situation, implement the key decisions and hand over, documented, to management or an internal team. No lasting dependency on the advisor is created. ### Does Ivo Schönberner also work for family offices? Yes. Family offices often hold investments across different industries and sizes. A situation picture per investment makes IT risks and costs comparable, without needing a large advisory team for every question. ### What documents does an IT due diligence need? Typical items are a system overview, contracts with IT providers, costs from recent years, roles and access rights, security concepts, incidents, certificates and audit reports. What is missing is itself a finding. ### How do CAPEX or OPEX in IT affect the value of an investment? That depends on the exit horizon and the valuation logic, not on a fixed rule. In a valuation based on EBITDA multiples, ongoing expenditure (OPEX) reduces EBITDA and therefore tends to reduce the multiple value, whereas capitalised investments (CAPEX) do not directly burden EBITDA but do tie up liquidity and free cash flow. Shortly before an exit, investments that a buyer will not pay for are usually avoided; with a long-term investment horizon, CAPEX for a platform that carries the business can make sense. The assessment belongs in the investment's IT situation picture. ### Does an investment need to be certified to ISO 27001, or is conformant work sufficient? Legally, conformant work that substantively meets the requirements of a standard, without being externally reviewed, is sufficient in most cases. In due diligence reviews, supplier assessments and customers' security questionnaires, a certificate still makes a big difference, because it creates trust without a review of your own and can shorten sales cycles. ## Does one of your investments have IT questions? Thirty minutes, no pitch. You describe the situation, I ask questions. After that, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/scale-ups · As of 2026-09-24 # From ten employees, IT is no longer a laptop. **Short answer:** It is about regulations, risks and the criticality of the business. And about whether the IT can carry the growth that executive management and investors are planning. I bring in the IT processes a growing company needs, and explain to executive management why it pays to know its situation before a customer, an investor or a regulator asks about it. ## What changes at around ten employees? IT no longer fits in one person's head. Devices turn into obligations, risks and costs. ### Access Who may see what? With every new hire and every departure, this becomes a security question. ### Customer data Data protection applies from the very first customer. In Switzerland, the FADP; with EU customers, also the GDPR. ### Customer requirements Larger customers send security questionnaires and ask about standards such as ISO 27001. ### Costs Subscriptions, licences and services grow unnoticed. No one has the overview. ## Why does IT become a regulatory question as a company grows? Because every new market, every corporate customer and every industry brings its own rules, which are met through IT. A Swiss scale-up with customers in Germany operates under the Swiss Data Protection Act and the GDPR at the same time. Anyone offering AI features in the EU falls under the EU AI Act. Anyone supplying vehicle manufacturers needs TISAX. Anyone building medical devices operates under the MedDO and the EU MDR. Which rule applies when is shown on the [Regulation](https://sacosi.ch/en/regulation) page. ## How do you build IT that can carry growth? With modern technology and no legacy baggage, documented from the outset, and with a cost logic that fits the funding. - **Identity first:** a central sign-on for everyone, with roles instead of individual rights. - **Centrally managed devices:** Mac and Windows with the same rules. - **Processes before tools:** clarify the workflows first, then choose the software. - **Environments separated from the outset:** dedicated development, test and production systems, plus a clean separation of customer tenants. Retrofitting this means rebuilding existing workflows and paying dearly for it. - **CAPEX and OPEX by design:** ongoing expense protects liquidity, while investments can be cheaper over time. The decision is made based on exit horizon, investor type and funding stage, not a fixed rule. - **Documented and auditable:** so that the next funding round, the first audit or the first corporate customer does not trigger a rebuild. - **Playbooks (documented procedures, SOPs):** operating and emergency procedures documented and auditable from the outset. ## Why should executive management know its situation? Because decisions made without a situation picture save or invest in the wrong place. Situational Awareness means being aware of the situation. The term comes from aviation, where errors rarely arise from a lack of technology but from an incorrect picture of the situation. It is the same in a growing company. That is why every engagement includes executive management being able, at the end, to explain for themselves which IT serves which goal. More on the [method from a founder's perspective](https://sacosi.ch/en/situational-awareness?rolle=gruender#gruender) and on the [films](https://sacosi.ch/en/concept). ## Questions from scale-ups. ### From what point does a company need an IT strategy? At the latest when IT no longer fits in one person's head. This is often the case around ten employees: roles, access, customer data, contracts and the first customer security requirements can no longer be managed on the side. ### What is different about IT for scale-ups? The pace. What is built today for twenty people must carry a hundred within a year, across several countries and under new regulations. Modern technology without legacy baggage makes this possible, if it is documented and built to scale from the outset. ### CAPEX or OPEX: how should IT be financed? That depends on the exit horizon, the valuation logic and the investor type, not on a fixed rule. Subscriptions and cloud services are ongoing expense (OPEX) and protect liquidity; with an exit approaching, this also avoids investments that a buyer often will not pay for. Owned hardware or locally operated systems are investments (CAPEX), which can be cheaper over time and are negotiable with a long-term investor. The decision belongs to financial planning and is set out in the decision log. ### Why separate development and production systems from the outset? Because otherwise errors, test data and experiments have a direct effect on live operations, and because customers, investors and auditors increasingly ask about it. Retrofitting development, test and production systems, along with the separation of customer tenants, means rebuilding existing workflows and paying considerably more than if the separation is planned in from the start. ### Which regulations come with growth? That depends on the industry and markets. With customers in the EU comes the GDPR, with corporate customers come security evidence requirements such as ISO 27001 or TISAX, with AI products the EU AI Act, and in critical sectors reporting obligations. An overview is on the Regulation page. ## Is your IT growing with your company? Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/succession · As of 2026-09-24 # IT situation picture before business succession. **Short answer:** Anyone handing over or taking over a company is dealing with more than figures. Financial due diligence does not show the condition of IT and technology, how much investment backlog is pending, or how strongly the company depends on individual people. Before a handover, I produce an IT situation picture, or, before a purchase, I check what a buyer is actually taking on, making risks, investment backlog and key-person dependencies identifiable before they become a point of dispute or a surprise. ## Which IT risks does a buyer take on? What does not appear on the balance sheet: investment backlog, security gaps, legacy licence and contract issues, and dependency on individual people. - **Investment backlog:** systems and devices that should long since have been renewed but keep running. - **Legacy security issues:** outdated software, open access points, missing or incomplete security concepts. - **Legacy licence and contract issues:** subscriptions, maintenance contracts and usage rights that are not readily transferable. - **Dependency on individual service providers:** can make the handover harder or more expensive if it only comes to light afterwards. - **Investments not yet written off:** IT investments (CAPEX) capitalised shortly before a handover, with their own useful life, are often not fully paid for by a buyer or are written down in the due diligence. Whether an investment still makes sense before a handover depends on the exit horizon, not on the previous funding habit. ## What does financial due diligence miss? Financial due diligence examines what can be expressed in figures. The condition of the technology is not part of that. - It examines revenue, costs, contracts and balance sheet items, not the technical substance behind them. - Investment backlog usually does not appear on the balance sheet at all, because it is a foregone investment, not a liability. - Key-person dependencies and undocumented knowledge are not visible in any financial metric. - Technical due diligence complements the financial one; it does not replace it. The same gap applies to portfolio holdings and investors, more on that under Investors and Family Offices. ## How do you identify key-person dependencies? When one person leaves and no one knows the access credentials, configurations or workflows, that is a key-person dependency, not a special case. - A key-person dependency map records which knowledge is tied to which person. - Typical signs: one name comes up for every technical question, access is not documented, there is no cover. - The map shows what documenting it or arranging cover costs, and where a handover is even possible without that person. ## When should an owner produce the IT situation picture? Well before the first approach to a buyer, so that findings can still be remedied rather than merely disclosed. - **Before the sale process:** investment backlog and key-person dependencies can still be remedied before a buyer negotiates them as a price deduction. - **During succession planning:** a successor from the family or the team needs the same handover documentation as an external buyer. - **For buyers:** the situation picture can also be produced after the initial approach, as your own technical due diligence, then serving as the basis for price negotiations. ## Questions about succession. What owners, successors and buyers most often ask before a handover. ### Which IT risks does a buyer take on in a business succession? Without their own review, a buyer takes on the condition of the IT as it is: open investment backlog, outdated or poorly maintained systems, ongoing licence and contract commitments, security gaps, and dependency on individual people or service providers. These risks often only become apparent months after the handover. ### What does financial due diligence miss in IT? Financial due diligence examines figures, contracts and balance sheet items. It does not show whether an application is technically outdated, whether investment backlog is pending, whether knowledge exists only in one person's head, or whether security gaps exist. These questions are answered by a technical due diligence, which complements the financial one, not replaces it. ### How do you identify key-person dependencies? Key-person dependencies show up when access credentials, passwords, configurations or workflows are known to only one person and are not documented anywhere. A key-person dependency map systematically records which knowledge is tied to which person, and shows what documenting it or arranging cover costs. ### When should an owner produce the IT situation picture before a handover? Well before the first approach to a buyer or the succession arrangement, so that investment backlog and key-person dependencies can still be remedied rather than merely disclosed. Even without a concrete sale plan, the situation picture is worthwhile as soon as a succession becomes foreseeable. ### What belongs in a technical due diligence for a succession? The architecture and condition of the systems, security and access, ongoing costs and contract terms, dependencies on people and service providers, the licence inventory and its transferability, and the question of whether the existing documentation is even sufficient for a new team. ### What does investment backlog mean, and how is it estimated? Investment backlog is technology that should long since have been renewed or replaced but keeps running because no one has approved the investment. It cannot be quantified to the exact franc, but it can be estimated as a range with reasoning for each item, so that buyer and seller have a common basis for negotiation. ## Is a succession or takeover coming up for you? Thirty minutes, no pitch. You describe the situation of the handover or the purchase, I ask questions. Afterwards, we both know whether an IT situation picture or a technical due diligence makes sense. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/regulation · As of 2026-09-24 # Which IT regulations apply to your company? **Short answer:** That depends on three things: your industry, your markets and your customers. A Swiss company operates under the Swiss Federal Act on Data Protection (FADP), and, with customers in the EU, also under the GDPR. EU laws such as NIS2 usually affect Swiss companies indirectly, through EU establishments or customers in the supply chain. Standards such as ISO 27001, ISO 9001 or TISAX are voluntary but are demanded contractually. This page classifies the most important rules and does not replace legal advice. ## What applies in Switzerland, what applies in the EU? All 22 rules in the knowledge base in one list: filter by scope of application, industry, bindingness and type, sort by name, next deadline or bindingness. Clicking on a rule shows how it applies in Switzerland and in the EU. As of: September 2026. For your own profile, use the Regulatory Check. Whether a rule applies in your specific case is clarified by the situation picture. ## Conformant or certified? Conformant does not mean certified — but in customer due-diligence reviews, it makes a real difference. - **Conformity** means: you meet the requirements and can demonstrate it, with documentation, approvals and records. - **Certification** means: an accredited body has audited and confirmed it. - **In practice,** customers ask about both in supplier assessments and security questionnaires. Demonstrable conformity shortens these reviews considerably, even without a certificate. ## How does a compliance roadmap come about? From the situation picture: first clarify which rules actually apply, then implement them in order of risk and business impact. - **Classify:** industry, markets, customers, products and data yield the list of obligations. - **Prioritise:** what is required by law, what customers demand, what investors expect. - **Build in:** requirements become part of the processes, not a folder on the side. - **Evidence:** versioned, approved, in an auditable system. IT am Main works the same way, certified to ISO 27001 and ISO 9001 since January 2025. This overview is a professional assessment, not legal advice. The legal assessment of any individual case belongs in a proper legal review. ## Sources Information as of: 24 September 2026. - [Federal Act on Data Protection (FADP), SR 235.1, in force since 1 September 2023](https://www.fedlex.admin.ch/eli/cc/2022/491/de) - [Regulation (EU) 2016/679, General Data Protection Regulation, Articles 3 and 27](https://eur-lex.europa.eu/eli/reg/2016/679/oj) - [Directive (EU) 2022/2555 (NIS2), in particular Articles 21 and 26](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) - [BSI: NIS2 Implementation Act enters into force, press release of 5 December 2025](https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html) - [Federal Office for Cybersecurity (BACS): reporting obligation for cyberattacks on critical infrastructure](https://www.bacs.admin.ch/de/meldepflicht) - [Regulation (EU) 2024/1689 (AI Act), as amended by Regulation (EU) 2026/1744, published on 24 July 2026](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) - [Federal Chancellery: Artificial intelligence, status of Swiss regulation](https://www.bk.admin.ch/de/ki) - [Regulation (EU) 2017/745 on medical devices](https://eur-lex.europa.eu/eli/reg/2017/745/oj) - [Swissmedic: New medical device regulation as of 26 May 2021](https://www.swissmedic.ch/swissmedic/en/home/news/mitteilungen/neue-regulierug-mep-26-05-2021.html) - [European Commission: Cyber Resilience Act, reporting obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting) - [Electricity Supply Ordinance (StromVV), amendment AS 2024 282 (ICT minimum standard, Article 5a)](https://www.fedlex.admin.ch/eli/oc/2024/282/de) - [FOCA: EU regulations on information security (Part-IS)](https://www.bazl.admin.ch/de/eu-verordnungen-zur-informationssicherheit-part-is) - [ENX Association: TISAX](https://enx.com/tisax) ## Questions about regulation. ### Does NIS2 apply to Swiss companies? Not directly. NIS2 is an EU directive. It affects Swiss companies through an establishment in the EU, because EU customers must demonstrate the security of their supply chain and pass this requirement on contractually, or if a company offers certain digital services such as cloud or managed services in the EU. In that case, a representative in the EU must be appointed. ### Since when has the new Swiss Data Protection Act applied? Since 1 September 2023. It applies to all companies that process personal data in Switzerland. Anyone serving customers in the EU must also observe the GDPR. ### Does the EU AI Act apply to Swiss companies? Yes, if they place AI systems on the market in the EU or if the output of their AI systems is used in the EU. The obligations have applied in stages since February 2025. The obligations for high-risk systems apply from December 2027, for AI in regulated products from August 2028. ### What is the difference between ISO 27001 and TISAX? ISO 27001 is an international standard for information security management systems, with a certificate. TISAX is an assessment procedure used by the automotive industry, based on the VDA ISA catalogue, with a label instead of a certificate, and is required contractually by vehicle manufacturers. ### Does the EU MDR apply in Switzerland? In Switzerland, the Medical Devices Ordinance (MedDO) applies, with Swissmedic as the supervisory authority. For access to the EU market, the EU MDR applies. Since 26 May 2021, the EU has treated Switzerland as a third country for medical devices, so Swiss manufacturers need an authorised representative in the EU. ### Must a start-up be certified to ISO 27001? Not by law. But corporate customers, tenders and investors often ask about it. It makes sense to build processes early on so that certification later is a small step, not a rebuild. ## Which rules apply to you? Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/industries · As of 2026-09-24 # Where an IT outage hits the business immediately. **Short answer:** I work primarily for industries where IT is critical: energy, manufacturing, MedTech and aviation. There, in addition to data protection and standards, separate rules apply, from the ICT minimum standard for electricity supply through TISAX and the medical devices ordinances to Part-IS in aviation. My largest engagements and the term Situational Awareness both come from aviation. ## [IT in energy supply](https://sacosi.ch/en/industries/energy) Security of supply depends on control systems and networks that must not fail. Typically relevant: ICT minimum standard under the Electricity Supply Ordinance (StromVV), reporting obligation for cyberattacks (Information Security Act, ISG), the NIS2 Directive, ISO/IEC 27001, the Swiss Federal Act on Data Protection (FADP). [More on energy](https://sacosi.ch/en/industries/energy) ## [IT in manufacturing](https://sacosi.ch/en/industries/manufacturing) A halt in production immediately costs revenue and the ability to deliver. Typically relevant: TISAX, the Cyber Resilience Act (CRA), the NIS2 Directive, ISO 9001, ISO/IEC 27001, the EU General Data Protection Regulation (GDPR). [More on manufacturing](https://sacosi.ch/en/industries/manufacturing) ## [IT in MedTech](https://sacosi.ch/en/industries/medtech) Approval and market access depend on complete documentation. Typically relevant: the EU Medical Device Regulation (MDR), ISO 9001, ISO/IEC 27001, the Cyber Resilience Act (CRA), the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), the EU AI Act. [More on MedTech](https://sacosi.ch/en/industries/medtech) ## [IT in aviation](https://sacosi.ch/en/industries/aviation) Flight operations do not forgive outages in the Operations Control Center. Typically relevant: Part-IS (aviation information security), ISO/IEC 27001, the NIS2 Directive, reporting obligation for cyberattacks (Information Security Act, ISG), the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR). [More on aviation](https://sacosi.ch/en/industries/aviation) ## And other industries? The method is the same. What matters is how critical IT is for the business, not the industry. The overview of all rules is under [Regulation](https://sacosi.ch/en/regulation). ## How critical is IT in your industry? Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/industries/energy · As of 2026-09-24 # IT in energy supply. **Short answer:** In energy supply, IT is part of critical infrastructure. In Switzerland, the ICT minimum standard under the Electricity Supply Ordinance (StromVV) has been mandatory since 1 July 2024, and cyberattacks must be reported to BACS within 24 hours since 1 April 2025. Companies with a branch or customers in the EU must also assess NIS2. I map these obligations to the company's situation and build the evidence so that ElCom, auditors and investors can review it. ## Why is IT critical in energy supply? - Security of supply depends on control systems and networks that must not fail. - Operational technology (OT) and office IT are converging, under different rules. - Growth in renewables, storage and new market roles brings new obligations. ## Which rules typically need to be checked? Whether a given rule applies in an individual case depends on size, markets, customers and products. The situation picture clarifies this. ### [ICT minimum standard under StromVV](https://sacosi.ch/en/regulation#stromvv) **Switzerland:** Mandatory since 1 July 2024. **EU:** Does not apply. ### [Reporting obligation for cyberattacks (ISG)](https://sacosi.ch/en/regulation#isg) **Switzerland:** Applies since 1 April 2025 to operators of critical infrastructure. **EU:** Does not apply. ### [NIS2 Directive](https://sacosi.ch/en/regulation#nis2) **Switzerland:** Not directly. Indirectly via EU subsidiaries, EU customers in the supply chain and for certain digital services. **EU:** Transposed into national law, in Germany since 6 December 2025. ### [ISO/IEC 27001](https://sacosi.ch/en/regulation#iso27001) **Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually. ### [Swiss Federal Act on Data Protection (FADP)](https://sacosi.ch/en/regulation#revdsg) **Switzerland:** Applies since 1 September 2023. **EU:** Does not apply directly. ## How can I help? ### [Situation picture for investments](https://sacosi.ch/en/investors) IT due diligence before the investment, or the situation picture in the first weeks afterwards: risks, costs, dependencies and obligations of the investment on a single page, with measures ranked by impact and effort. ### [Fractional CTO for a defined period](https://sacosi.ch/en/fractional-cto) Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is a handover to a permanent CTO or the company's own team. ### [Compliance roadmap](https://sacosi.ch/en/regulation) Which standards and laws apply to your business, in what order to address them, and how the evidence is built up in an auditable system, for example for ISO 27001, ISO 9001 or TISAX. ### [Scaling architecture](https://sacosi.ch/en/it-architecture) A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, costs in proportion to budget. Back to the [industry overview](https://sacosi.ch/en/industries) or the [overview of all rules](https://sacosi.ch/en/regulation). ## What is the situation in your company? Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/industries/manufacturing · As of 2026-09-24 # IT in manufacturing. **Short answer:** For manufacturing companies, IT obligations often arrive via customers: automotive manufacturers require TISAX from their suppliers, EU customers often pass NIS2 requirements down their supply chain, and anyone selling connected products in the EU is subject to the Cyber Resilience Act, whose reporting obligations have applied since 11 September 2026. I clarify which obligations genuinely affect your business and build them into the processes that ISO 9001 and ISO 27001 require in any case. ## Why is IT critical in manufacturing? - A production stoppage immediately costs revenue and delivery capability. - Customers assess suppliers' information security before placing orders. - Products with embedded software bring their own manufacturer obligations. ## Which rules typically need to be checked? Whether a given rule applies in an individual case depends on size, markets, customers and products. The situation picture clarifies this. ### [TISAX](https://sacosi.ch/en/regulation#tisax) **Switzerland:** Contractual, in the automotive supply chain. **EU:** Contractual, in the automotive supply chain. ### [Cyber Resilience Act (CRA)](https://sacosi.ch/en/regulation#cra) **Switzerland:** Applies to Swiss manufacturers selling products with digital elements in the EU. **EU:** Reporting obligations since 11 September 2026, full application from 11 December 2027. ### [NIS2 Directive](https://sacosi.ch/en/regulation#nis2) **Switzerland:** Not directly. Indirectly via EU subsidiaries, EU customers in the supply chain and for certain digital services. **EU:** Transposed into national law, in Germany since 6 December 2025. ### [ISO 9001](https://sacosi.ch/en/regulation#iso9001) **Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually. ### [ISO/IEC 27001](https://sacosi.ch/en/regulation#iso27001) **Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually. ### [EU General Data Protection Regulation (GDPR)](https://sacosi.ch/en/regulation#dsgvo) **Switzerland:** Applies to Swiss companies that offer goods or services to individuals in the EU or monitor their behaviour. **EU:** Applies since 25 May 2018. ## How can I help? ### [Situation picture for investments](https://sacosi.ch/en/investors) IT due diligence before the investment, or the situation picture in the first weeks afterwards: risks, costs, dependencies and obligations of the investment on a single page, with measures ranked by impact and effort. ### [Fractional CTO for a defined period](https://sacosi.ch/en/fractional-cto) Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is a handover to a permanent CTO or the company's own team. ### [Compliance roadmap](https://sacosi.ch/en/regulation) Which standards and laws apply to your business, in what order to address them, and how the evidence is built up in an auditable system, for example for ISO 27001, ISO 9001 or TISAX. ### [Scaling architecture](https://sacosi.ch/en/it-architecture) A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, costs in proportion to budget. Back to the [industry overview](https://sacosi.ch/en/industries) or the [overview of all rules](https://sacosi.ch/en/regulation). ## What is the situation in your company? Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/industries/medtech · As of 2026-09-24 # IT in medical technology. **Short answer:** MedTech companies in Switzerland operate under two regimes: the Swiss Medical Devices Ordinance (MedDO), with Swissmedic as the supervisory authority, and, for the EU market, the EU Medical Device Regulation (MDR). Since 26 May 2021, Switzerland has been treated as a third country under this regulation. IT supports quality management, traceability and the security of software and connected products. I align it so that the evidence for audits and approval arises directly from operations. ## Why is IT critical in medical technology? - Approval and market access depend on complete documentation. - Software can itself be a medical device, with its own requirements. - Growth into the EU brings authorised representatives, a second register and duplicate evidence. ## Which rules typically need to be checked? Whether a given rule applies in an individual case depends on size, markets, customers and products. The situation picture clarifies this. ### [EU Medical Device Regulation (MDR)](https://sacosi.ch/en/regulation#mdr) **Switzerland:** Swiss law: Medical Devices Ordinance (MedDO), supervised by Swissmedic. For the EU, Switzerland has been treated as a third country since 26 May 2021. **EU:** Applies since 26 May 2021. ### [ISO 9001](https://sacosi.ch/en/regulation#iso9001) **Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually. ### [ISO/IEC 27001](https://sacosi.ch/en/regulation#iso27001) **Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually. ### [Cyber Resilience Act (CRA)](https://sacosi.ch/en/regulation#cra) **Switzerland:** Applies to Swiss manufacturers selling products with digital elements in the EU. **EU:** Reporting obligations since 11 September 2026, full application from 11 December 2027. ### [Swiss Federal Act on Data Protection (FADP)](https://sacosi.ch/en/regulation#revdsg) **Switzerland:** Applies since 1 September 2023. **EU:** Does not apply directly. ### [EU General Data Protection Regulation (GDPR)](https://sacosi.ch/en/regulation#dsgvo) **Switzerland:** Applies to Swiss companies that offer goods or services to individuals in the EU or monitor their behaviour. **EU:** Applies since 25 May 2018. ### [EU AI Act](https://sacosi.ch/en/regulation#aiact) **Switzerland:** Applies to Swiss providers that place AI systems on the EU market or whose outputs are used in the EU. **EU:** Phased in since 2 February 2025. ## How can I help? ### [Situation picture for investments](https://sacosi.ch/en/investors) IT due diligence before the investment, or the situation picture in the first weeks afterwards: risks, costs, dependencies and obligations of the investment on a single page, with measures ranked by impact and effort. ### [Fractional CTO for a defined period](https://sacosi.ch/en/fractional-cto) Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is a handover to a permanent CTO or the company's own team. ### [Compliance roadmap](https://sacosi.ch/en/regulation) Which standards and laws apply to your business, in what order to address them, and how the evidence is built up in an auditable system, for example for ISO 27001, ISO 9001 or TISAX. ### [Scaling architecture](https://sacosi.ch/en/it-architecture) A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, costs in proportion to budget. Back to the [industry overview](https://sacosi.ch/en/industries) or the [overview of all rules](https://sacosi.ch/en/regulation). ## What is the situation in your company? Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/industries/aviation · As of 2026-09-24 # IT in aviation. **Short answer:** In aviation, an IT outage immediately affects flight operations. Since October 2025 and February 2026, the EU information security requirements (Part-IS) have required aviation organisations to operate a dedicated information security management system, implemented in Switzerland by the Federal Office of Civil Aviation (FOCA). This is the environment from which the term Situational Awareness comes, and my own work: building the IT for Discover Airlines and the IT for FraAlliance, both with IT am Main. ## Why is IT critical in aviation? - Flight operations do not tolerate outages in the Operations Control Center. - Group standards, shareholders and supervisory authorities impose requirements at the same time. - New companies must deliver from day one. ## Which rules typically need to be checked? Whether a given rule applies in an individual case depends on size, markets, customers and products. The situation picture clarifies this. ### [Part-IS (aviation information security)](https://sacosi.ch/en/regulation#partis) **Switzerland:** Implemented by the Federal Office of Civil Aviation (FOCA). **EU:** Since 16 October 2025 and 22 February 2026, depending on the organisation. ### [ISO/IEC 27001](https://sacosi.ch/en/regulation#iso27001) **Switzerland:** Voluntary, often required contractually. **EU:** Voluntary, often required contractually. ### [NIS2 Directive](https://sacosi.ch/en/regulation#nis2) **Switzerland:** Not directly. Indirectly via EU subsidiaries, EU customers in the supply chain and for certain digital services. **EU:** Transposed into national law, in Germany since 6 December 2025. ### [Reporting obligation for cyberattacks (ISG)](https://sacosi.ch/en/regulation#isg) **Switzerland:** Applies since 1 April 2025 to operators of critical infrastructure. **EU:** Does not apply. ### [Swiss Federal Act on Data Protection (FADP)](https://sacosi.ch/en/regulation#revdsg) **Switzerland:** Applies since 1 September 2023. **EU:** Does not apply directly. ### [EU General Data Protection Regulation (GDPR)](https://sacosi.ch/en/regulation#dsgvo) **Switzerland:** Applies to Swiss companies that offer goods or services to individuals in the EU or monitor their behaviour. **EU:** Applies since 25 May 2018. ## What aviation mandates lie behind this? Two programmes within the Lufthansa Group environment, both delivered with IT am Main. - **Discover Airlines, 2021 to 2026:** building IT from an empty office, growth to around 2’200 employees, network connection of the Operations Control Center, a prepared handover to the group IT function. - **FraAlliance, from 2022:** standalone IT for the joint venture of Fraport and Lufthansa in under four months. ## How can I help? ### [Situation picture for investments](https://sacosi.ch/en/investors) IT due diligence before the investment, or the situation picture in the first weeks afterwards: risks, costs, dependencies and obligations of the investment on a single page, with measures ranked by impact and effort. ### [Fractional CTO for a defined period](https://sacosi.ch/en/fractional-cto) Technical leadership for a defined period: architecture, team, security, due-diligence readiness. The goal is a handover to a permanent CTO or the company's own team. ### [Compliance roadmap](https://sacosi.ch/en/regulation) Which standards and laws apply to your business, in what order to address them, and how the evidence is built up in an auditable system, for example for ISO 27001, ISO 9001 or TISAX. ### [Scaling architecture](https://sacosi.ch/en/it-architecture) A target architecture without legacy baggage that supports the planned growth: identity, workplace, cloud, local AI, costs in proportion to budget. Back to the [industry overview](https://sacosi.ch/en/industries) or the [overview of all rules](https://sacosi.ch/en/regulation). ## What is the situation in your company? Thirty minutes, no presentation. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/fractional-cto · As of 2026-09-24 # Fractional CTO for start-ups and scale-ups. **Short answer:** As Fractional CTO, I take on the technical leadership of your company part time or for a defined period: architecture, team, security and due diligence readiness. I work according to Situational Awareness: technology follows your business model, not the other way round. The goal is the handover to a permanent CTO or to your team. ## When do you need a Fractional CTO? When technical leadership is needed quickly, but a full-time role does not yet fit or has not yet been filled. ### There is no CTO The product is growing, and decisions on architecture and team are made on the side. ### The CTO is leaving Knowledge risks being lost, the team needs leadership, and the search takes time. ### Due diligence is coming Investors want to see architecture, security and scalability, and want it evidenced. ### The platform can no longer carry the load What was built for a hundred customers breaks at a thousand. Quick fixes become expensive. ## What happens in the first 90 days? In the first 90 days, a reliable picture of the situation emerges, together with the first wave of decisions the business feels immediately. - **Days 1 to 30, capturing the situation:** conversations with founders, investors, the team and key customers. Goals, vision, funding stage and runway, core processes, plus architecture, costs and security. Result: the situation picture with a SWOT analysis and process map. - **Days 31 to 60, understanding the situation:** naming the biggest points of friction between product and technology, making decisions and recording them in the decision log. - **Days 61 to 90, thinking ahead:** target architecture and roadmap for the next 12 to 24 months, a role profile for the permanent CTO or for expanding the team. - **Game plan:** target architecture and roadmap from days 61 to 90. ## What do investors want to see in an IT due diligence? Investors check whether the technology can carry the business model, and whether the knowledge about it depends on more than one person. - an understandable architecture and the reasoning behind the key decisions - security, access rights and data protection, evidenced rather than asserted - scalability and the costs that come with growth - dependencies on individual people and vendors - a team and a roadmap that fit the business plan and the funding - documentation that can be audited, instead of knowledge kept in people's heads ## What can the collaboration look like? - **Fractional:** one to three days a week over several months. - **Interim:** full time for a transition period, until the permanent CTO starts. - **Due diligence sprint:** targeted preparation for a funding round or transaction. For investors and family offices, the same is available as an engagement within a portfolio holding: [IT situation picture and due diligence](https://sacosi.ch/en/investors). Every format ends with a documented handover. What that looks like is described in the [Situational Awareness method](https://sacosi.ch/en/situational-awareness). ## Questions about the Fractional CTO. ### What does a Fractional CTO do? A Fractional CTO takes on the technical leadership of a company part time or for a defined period. He is responsible for architecture, technology decisions, security and building the team, without the company having to hire a full-time executive straight away. ### When does a Fractional CTO pay off? There are typically four situations: there is not yet a CTO, the previous CTO is leaving, a funding round or due diligence is coming up, or the platform can no longer carry the growth. In all four cases, technical leadership is needed quickly, but not necessarily on a permanent basis. ### How much time does Ivo Schönberner invest as Fractional CTO? That depends on the situation. Typical arrangements are one to three days a week, or a monthly engagement with a fixed scope. The framework is set out in the initial call. ### What is the difference between a Fractional CTO and an Interim CTO? An Interim CTO usually replaces a missing executive full time for a transition period. A Fractional CTO works part time, often over a longer period. Ivo Schönberner takes on both forms, depending on what the situation calls for. ### Does a Fractional CTO help with an IT due diligence? Yes. He prepares architecture, security, documentation and the team so that investors can review what they want to review, and accompanies the conversations with the reviewers. ## Do you need technical leadership? Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/it-architecture · As of 2026-09-24 # IT architecture for companies with up to 1’000 employees. **Short answer:** As IT architect, I design a target architecture derived from how your business works, not from a vendor catalogue. Topics include identity, workplace with Mac and Windows, cloud and on-premises operation, AI with sensitive data, and compliance by design. You receive an architecture diagram, a decision log and a roadmap. ## Which topics does the target architecture cover? A target architecture is only as good as its connection to the business. That is why every topic starts with the question of which process it supports. ### Identity and access Who may do what, from where, with which device. The basis for security and audit. ### Workplace Mac and Windows on equal footing, centrally managed, with the same rules. ### Cloud and on-premises operation What belongs in the cloud and what stays in-house, decided on reasoned grounds rather than dogma. ### AI with sensitive data Locally operated models, where data must not leave the premises. ### Data and applications Which systems are the system of record and how information flows, without shadow lists. ### Compliance by design ISO 27001, the FADP, the GDPR and industry requirements as part of the architecture, not as an add-on. ## How does the target architecture come about? In short, intensive rounds with executive management and business units, not in the ivory tower of IT. - **Situation assessment:** interviews with executive management, business units and IT on goals, core processes and budget, a SWOT analysis, review of existing systems and contracts. - **Target architecture workshop:** jointly translating the requirements of the business into architecture decisions. - **Elaboration:** architecture diagram, decision log, roadmap with effort estimates and dependencies. - **Support:** implementation on request, together with your IT team or with IT am Main. ## What is on the table at the end? - **Process map and process flows:** which core processes the architecture must support, with systems and handovers. - **Architecture diagram:** a representation that executive management and IT can read equally well. - **Decision log:** every decision with its trigger, options and reasoning. - **Roadmap:** sequence, effort, cost relative to budget, dependencies and quick wins. - **Game plan:** the roadmap with effort and cost relative to budget. - **Auditable documentation:** kept conformant, for example with ISO 27001, versioned and approved. - **Situation picture:** the page from which everything is derived. More on this under [Situational Awareness](https://sacosi.ch/en/situational-awareness). ## Questions about IT architecture. ### For which company sizes does Ivo Schönberner work as IT architect? Mainly for companies with around 50 to 1’000 employees, often SMEs and companies in regulated industries. At this size, IT is too complex for improvisation, but usually without its own architecture department. ### What is a target architecture? A target architecture describes what a company's IT should look like in twelve to 36 months: identities, workplaces, applications, data, operations and security, derived from the processes and goals of the business, with a roadmap to get there. ### Does Ivo Schönberner work with Mac and Windows? Yes. He plans workplaces with Mac and Windows on equal footing, including device management, identity and security, so that both worlds meet the same rules. ### When should AI run locally instead of in the cloud? When data is confidential, personal or regulated and must not or should not go to third parties. In that case, a locally operated model can be the more sensible choice. The decision depends on data, cost and requirements and is set out in the decision log. ### What is compliance by design? Compliance by design means that requirements such as ISO 27001, the Swiss Federal Act on Data Protection (FADP), the GDPR or industry requirements are built into the architecture from the outset, rather than added on later. That saves rework and makes audits predictable. ## Does your IT still fit your business? Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/project-leadership · As of 2026-09-24 # IT project leadership in the enterprise environment. **Short answer:** As project leader, I steer IT programmes in corporate groups, group companies and joint ventures: greenfield build-outs, carve-in, carve-out, aviation. I connect shareholders with different standards, keep decisions on record with evidence, and hand over cleanly to the line organisation at the end. ## Which programmes do I lead? Programmes in which the business, the shareholders and IT are all in motion at the same time. ### Greenfield A new company needs, from day one, IT that meets group standards. ### Joint venture Two shareholders, two IT worlds, one shared working environment. ### Carve-in and carve-out Separating out or integrating units, without operations stalling. ### Aviation IT in flight operations, where outages hit the business immediately. ## Which projects lie behind this? The method emerged from two programmes in the Lufthansa Group environment, both delivered with IT am Main. - **Discover Airlines, 2021 to 2026:** IT build-out from an empty office, growth to around 2’200 employees at the Frankfurt and Munich hubs, network connection of the Operations Control Center, prepared handover to the group IT. - **FraAlliance, from 2022:** standalone IT for the joint venture between Fraport and Lufthansa in under four months, with central identity and the compliance requirements of the Lufthansa Group. ## How do I steer a programme? - **Situation picture before the plan:** before the project plan is set, the goals, budget and interests of all shareholders and stakeholders are captured, for example in a stakeholder matrix. - **Decision log:** every decision is documented with reasoning and approval, traceable for both shareholders and for audits. - **Contracts and statements of work:** scope, budget and acceptances are steered against the statement of work, not against recollections. - **Audit-proof documentation:** process flows, a RACI matrix and evidence, kept conformant in an auditable system, so that shareholders and auditors see the same status. - **Handover to the line organisation:** the programme ends when the organisation carries it on its own. - **Line-up:** roles and responsibilities in the RACI matrix. - **Playbooks for the line organisation (documented procedures, SOPs):** the handover documentation with which the organisation carries the programme on its own. ## Questions about project leadership. ### Which enterprise projects has Ivo Schönberner led? With IT am Main, among others, the IT build-out for Discover Airlines from 2021 to 2026, with a prepared handover to the Lufthansa Group's IT, and the IT build-out for FraAlliance, the joint venture between Fraport and Lufthansa, in under four months. ### What is special about IT projects in joint ventures? Two or more shareholders bring their own IT standards, security rules and approval paths. The project leadership must connect these worlds without violating either one, and must be able to evidence every decision to both sides. ### Does Ivo Schönberner also take on carve-outs and carve-ins? Yes. Separating a unit out of a group (carve-out) or integrating one into a group (carve-in) are situations where Situational Awareness has a particular effect, because the business and IT are in motion at the same time. ### How does Ivo Schönberner report as project leader? With evidence, not status slides: decisions in the decision log, progress against verifiable results, risks with owners and dates. ### Does Ivo Schönberner have experience in aviation? Yes. Two of his largest engagements were in the Lufthansa Group environment, including Discover Airlines with the network connection of the Operations Control Center, and FraAlliance in Frankfurt. ## Is a programme coming up? Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/about · As of 2026-09-24 # About Ivo Schönberner. **Short answer:** Ivo Schönberner is an IT entrepreneur and advisor based in Zürich and Frankfurt am Main, founder of SACOSI and managing director of IT am Main GmbH. He advises executive management, investors and family offices in Switzerland and Germany, primarily at start-ups, scale-ups and ventures, as a fractional CTO, IT architect, project lead and sparring partner. His advisory product is called Situational Awareness: IT that fits the business, not the other way round. ## In a few sentences Ivo Schönberner builds IT that first understands the situation of the business. As managing director of IT am Main GmbH, he took Discover Airlines' IT from zero to around 2’200 employees and built FraAlliance's IT in under four months. He advises from Zürich and Frankfurt. **"IT must fit the business, not the business the IT."** ## Thinking systemically, not treating symptoms Ivo Schönberner does not solve the individual problem; he builds the architecture from which it no longer arises. Four pieces of evidence show the pattern, rather than merely asserting it. Automation ### The process that builds processes Instead of automating one more process, he built the infrastructure on which even small companies get system-based, ISO-conformant automation they could otherwise not afford. Minimal privileges and documentation in quality and risk management are built in from the outset. CRM decision ### Data model along Article 9 GDPR For a CRM decision, he adopted the generic data model of a large provider and discarded the rest. The decisive factor was Article 9 GDPR for health data. Result: a self-hosted solution that combines function and data protection, instead of adapting the business to the tool. Discover Airlines · 2021–2026 ### IT from zero to around 2’200 employees As Chief Architect, he built Discover Airlines' IT from the ground up, including the network connection of the Operations Control Center, with a prepared handover to the Lufthansa Group's corporate IT. FraAlliance · from 2022 ### Independent IT in under four months For FraAlliance, the joint venture of Fraport and Lufthansa Group, he defined the IT target operating model and built the independent IT in under four months. ## Six core values Not as a list of adjectives, but with the behaviour by which they can be recognised. 01 ### Plain speaking and honesty He says what he thinks, even when it is uncomfortable. Recognisable in that he also advises against plans that would bring short-term revenue but do not serve the business. 02 ### Systems thinking He does not solve the symptom; he builds the architecture from which the problem no longer arises. Recognisable in that he clarifies the target picture and dependencies before the first implementation step. 03 ### Personal accountability He takes ownership of the result, not just the task. Recognisable in that he takes on critical projects himself again to secure quality and customer benefit. 04 ### Substance over visibility What counts is business benefit, not appearance. Recognisable in that he measures decisions against the business requirement, not against technology fashion. 05 ### Structure and demonstrability Clear architecture, clear roles, clean documentation. Recognisable in that he thinks function and compliance together from the outset, as a frame around every solution. 06 ### Reliability under pressure He stays capable of acting when things get hectic. Recognisable in that in escalations and crises he prioritises calmly rather than reacting. ## American football, national team Before Ivo Schönberner became an entrepreneur, he stood on the field as an American football player: national player, European champion in 2014 and 2016. American football · National player · **European champion in 2014 and 2016** · Squad number 44 What has stayed from that time shapes his way of working to this day: a clear head when the pressure rises, because performance is decided in the situation, not in the plan. Preparation and repetition beat talent; the result is created in the invisible work beforehand. And every position has a task, the system wins, not the individual — this is exactly how he cuts roles and responsibilities for clients today. What has stayed is the eye for the line-up: every position has a task, the system wins, not the individual. ## How the collaboration works - **The situation first, then the technology.** He builds nothing before he has understood what the business needs. - **Evidence instead of promises.** Decisions are recorded in the decision log, results are verifiable. - **Responsibility stays with the company.** He prepares decisions and implements what has been decided. - **He works towards the handover.** Grow. Scale. Let go. - **Playbooks for the handover (documented procedures, SOPs).** Grow. Scale. Let go. What you can expect - Plain speaking instead of diplomacy, even when it is uncomfortable. - A counterpart who thinks along and sees connections. - Responsibility for the result, not just the task. What he expects - A genuine sparring partner, not someone who just agrees. - Openness to uncomfortable truths. - The willingness to work on the matter, not on the status. ## What he does not do - He is not someone who just agrees, nor a diplomat who smiles away what is uncomfortable. - He does not deliver tactical individual fixes that merely postpone the actual problem. - He does not do technology for its own sake, and no buzzword consulting. - He does not bend the business to fit the tool; he bends the tool to fit the business. - He does not sell anything that does not genuinely benefit the client, just because it brings short-term revenue. ## Quotable sentences > IT must fit the business, not the business the IT. > > — Ivo Schönberner > I do not solve the symptom, I build the architecture from which the problem no longer arises. > > — Ivo Schönberner > I tell you what you need to hear, not what you want to hear. > > — Ivo Schönberner > I take ownership of the result, not just the task. > > — Ivo Schönberner ## Why Zürich and Frankfurt? Because his engagements are in both countries and the distance between the two cities is short enough to be on site when it matters. Zürich is his base for engagements in Switzerland. Frankfurt is the registered office of IT am Main and is close to his aviation engagements. He works in German and English, on site and remotely. ## Frequently asked questions about Ivo Schönberner. ### Who is Ivo Schönberner? Ivo Schönberner is an IT entrepreneur and advisor based in Zürich and Frankfurt am Main. He is managing director of IT am Main GmbH and founder of the advisory brand SACOSI, and advises executive management, investors and family offices in Switzerland and Germany, primarily at start-ups, scale-ups and ventures. ### What does Situational Awareness mean for Ivo Schönberner? Situational Awareness is his advisory product: IT is derived from the situation of the company, that is, from goals, core processes, finances and the interests of investors and stakeholders, instead of adapting the business to a system. It is based on Mica Endsley's three-level model (1995), extended with a fourth step: lead and hand over. ### What is Ivo Schönberner's background? Before his career as an entrepreneur, Ivo Schönberner was an American football player and national player, European champion in 2014 and 2016. As managing director of IT am Main GmbH, he built, among other things, Discover Airlines' IT from zero to around 2’200 employees and set up an independent IT for the joint venture FraAlliance in under four months. ### How does Ivo Schönberner approach IT problems? Systemically: he does not solve the symptom; he builds the architecture from which the problem no longer arises. Decisions are prepared, documented and made demonstrable before they are implemented. ### Where does Ivo Schönberner work? From Zürich and Frankfurt am Main, with engagements in Switzerland and Germany, on site and remotely, in German and English. ## What is your situation? Thirty minutes, no pitch. You describe the situation, I ask questions. After that, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English --- Source: https://sacosi.ch/en/contact · As of 2026-09-24 # Contact. **Short answer:** Fastest via a 30-minute initial call. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile and which engagement model fits. ### Appointment Book an initial call ### Email welcome@sacosi.ch ### Switzerland Zürich · +41 78 251 09 69 ### Germany Frankfurt am Main · +49 152 27602667 ## How is your situation? Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile. CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English